Researchers Map SpiceRAT-Linked Infrastructure Impersonating Central Asian Government and Energy Targets

Summary
Hunt.io researchers linked SpiceRAT infrastructure to hosts associated with NodeEdgeRAT and NomadRAT, identifying domains impersonating government, energy, and telecom organizations across Central Asia. The findings indicate infrastructure links, not confirmed victimir
Key points
- Researchers tracked a cluster of SpiceRAT command-and-control servers active from late 2025 through August 2026, linking hosts through shared hostnames, TLS certificates, and webpage hashes.
- Shared registration-level infrastructure connects hosts attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT; the research cannot establish whether one operator or multiple operators used the infrastructure.
- Domains and certificates impersonated organizations including Uzbekistan's railway authority, Turkmenistan's energy and foreign-affairs entities, and Tajikistan's telecom provider.
- Thirteen servers hosted an identical copy of RTX Corporation's homepage; researchers found no credential forms, payloads, or delivery mechanisms in the page.
- Passive DNS records show related subdomain infrastructure dating to at least mid-2022.
- The analysis used internet-wide scan data and did not investigate malware behavior, delivery, or initial access; named organizations are apparent impersonation targets, not confirmed compromised victims.
Article Details
- Attack Vectors
- The article examines command-and-control infrastructure and explicitly does not assess malware delivery or initial access.
- SpiceRAT command traffic operated on port 443, separate from a cloned RTX Corporation homepage served on port 80 as likely static decoy content.
- Domains and certificates impersonated Central Asian government bodies, state enterprises, and energy and telecommunications entities. The named organizations are apparent impersonation targets, not confirmed compromised parties.
- Some cluster hosts exposed RDP-over-TLS on unusually high ports.
- Shared hostnames, TLS certificates, webpage content, and domain registrations connected infrastructure associated with SpiceRAT, NodeEdgeRAT, and NomadRAT; the research does not establish whether one operator or multiple operators controlled it.
- Defensive Notes
- Organizations in the affected regions and sectors can check the published infrastructure indicators against their own exposure.
- A byte-identical copy of the RTX Corporation homepage produced a SHA-256 page hash observed on 13 cluster servers; the article says no other host in Hunt.io's dataset served that page.
- The article cautions that a SpiceRAT server detection identifies what is running on a host, not who operates it.
- The TLC certificate issuer alone is not an indicator: the researchers observed nearly 3,000 servers with TLC certificates in a 30-day scan window.
- The researchers notified affected organizations and relevant national CERTs before publication; notification does not mean recipients confirmed the findings.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | hoster-kg[.]com | Shared registered parent domain linking a cluster hostname to a Bitdefender-attributed NodeEdgeRAT hostname. |
| DOMAIN | infocomkg[.]org | Parent domain of enumerated cluster-linked hostnames. |
| DOMAIN | kginfocom[.]com | Historical infrastructure attributed in the article to IndigoZebra. |
| DOMAIN | natcommunzu[.]com | Parent domain of enumerated cluster infrastructure, including a hostname detected as SpiceRAT. |
| DOMAIN | post[.]mfa-uz[.]com | Historical infrastructure attributed in the article to IndigoZebra. |
| DOMAIN | tdtu[.]org | Shared registered parent domain linking a cluster hostname to a Bitdefender-published NomadRAT C2 hostname. |
| DOMAIN | tm-mfa[.]com | Domain described as impersonating Turkmenistan's Ministry of Foreign Affairs. |
| DOMAIN | tmgaz-server[.]com | Domain described as spoofing Türkmengaz on a cluster server. |
| DOMAIN | tojiktelecomtj[.]com | Domain described as targeting Tojiktelecom on a cluster server. |
| HOSTNAME | api[.]hpsupporter[.]com | Hostname on a cluster-linked host exposing high-port RDP-over-TLS. |
| HOSTNAME | azure[.]adm-devon[.]com | Cluster hostname impersonating Uzbekistan government administration. |
| HOSTNAME | azure[.]uzrailwaystax[.]com | Cluster hostname and TLS certificate subject impersonating Uzbekistan's railway authority. |
| HOSTNAME | center[.]infocomkg[.]org | Hostname on a cluster-linked server exposing high-port RDP-over-TLS. |
| HOSTNAME | center[.]yntymak-ordo[.]com | Hostname in the indicator table for impersonation of the Kyrgyzstan president's residence. |
| HOSTNAME | cert[.]presldent[.]info | Hostname in enumerated government-themed cluster infrastructure. |
| HOSTNAME | check[.]presldent[.]info | Hostname in enumerated government-themed cluster infrastructure. |
| HOSTNAME | checkup[.]hpsupporter[.]com | Hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | chief[.]presldent[.]info | Historical hostname in enumerated government-themed cluster infrastructure. |
| HOSTNAME | data[.]yntymak-ord[.]com | Kyrgyzstan government-themed hostname in the indicator table. |
| HOSTNAME | data[.]yntymak-ordo[.]com | Cluster hostname identified as impersonating the Kyrgyzstan president's residence. |
| HOSTNAME | evo[.]hoster-kg[.]com | Sibling hostname Bitdefender attributed to NodeEdgeRAT. |
| HOSTNAME | gov[.]mpekz[.]online | Cluster hostname referencing a Kazakh government entity. |
| HOSTNAME | help[.]galkynysh[.]net | Hostname impersonating Turkmenistan's Galkynysh gas field. |
| HOSTNAME | help[.]hoster-kg[.]com | Cluster hostname sharing a registered parent domain with a Bitdefender-attributed NodeEdgeRAT hostname. |
| HOSTNAME | help[.]hpsupporter[.]com | Hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | info[.]tdtu[.]org | Historical hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | infoxxe[.]plan-mail[.]com | Hostname of a cluster server serving the cloned RTX page. |
| HOSTNAME | infrastructure[.]minings[.]blog | Hostname of a Bitdefender-reported SpiceRAT server. |
| HOSTNAME | it[.]presldent[.]info | Hostname in enumerated government-themed cluster infrastructure. |
| HOSTNAME | kg[.]cwisuz[.]com | Hostname listed on a server impersonating Central Asian entities. |
| HOSTNAME | kg[.]tdtu[.]org | Cluster hostname sharing a registered parent domain with a Bitdefender-published NomadRAT C2 hostname. |
| HOSTNAME | link[.]ytnymak-ord[.]com | Kyrgyzstan government-themed hostname in the indicator table. |
| HOSTNAME | mail[.]infocomkg[.]org | Hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | mail[.]plan-mail[.]com | Hostname of a cluster server serving the cloned RTX page. |
| HOSTNAME | mail[.]postmfa[.]com | Hostname on a cluster-linked server exposing high-port RDP-over-TLS. |
| HOSTNAME | manager[.]skycom[.]support | Bitdefender-listed SpiceRAT hostname that also resolved to two additional servers. |
| HOSTNAME | microsoft[.]natcommunzu[.]com | Hostname in enumerated communications-themed cluster infrastructure. |
| HOSTNAME | mineconom[.]tdtu[.]org | Bitdefender-published NomadRAT C2 hostname. |
| HOSTNAME | normativ[.]dushanbeidc[.]org | Cluster hostname impersonating Tajikistan's national IT-hub project. |
| HOSTNAME | normativ[.]sozandagon[.]org | Hostname listed on a server impersonating Central Asian entities. |
| HOSTNAME | ns[.]panterstationary[.]online | Hostname of a cluster server serving the cloned RTX page. |
| HOSTNAME | ns1[.]wordcheck[.]info | Hostname listed for a Hunt.io-detected SpiceRAT cluster server. |
| HOSTNAME | ns2[.]asiainfo[.]it[.]com | Hostname reused across multiple SpiceRAT servers. |
| HOSTNAME | pro[.]taustas[.]com | Hostname of a cluster server serving the cloned RTX page. |
| HOSTNAME | sanly[.]oilgas-tm[.]com | Cluster hostname impersonating Turkmen energy interests. |
| HOSTNAME | service[.]infocomkg[.]org | Hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | state[.]presldent[.]info | Cluster hostname using a government-themed typosquat. |
| HOSTNAME | storage[.]natcommunzu[.]com | Cluster-linked hostname whose host Hunt.io flagged for SpiceRAT. |
| HOSTNAME | support[.]natcommunzu[.]com | Historical hostname in enumerated communications-themed cluster infrastructure. |
| HOSTNAME | telecom[.]hpsupporter[.]com | Hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | tmk[.]natcommunzu[.]com | Cluster hostname described as a possible spoof of Uzbekistan's communications sector. |
| HOSTNAME | ud[.]tdtu[.]org | Historical hostname in enumerated cluster-linked infrastructure. |
| HOSTNAME | uz[.]adm-devon[.]com | Uzbekistan government-themed hostname in the indicator table. |
| HOSTNAME | uz[.]natcommunzu[.]com | Historical hostname in enumerated communications-themed cluster infrastructure. |
| HOSTNAME | uzrailway[.]devon-uz[.]com | Bitdefender-published BloodAlchemy C2 hostname impersonating Uzbekistan's railway entity. |
| HOSTNAME | www[.]tm-mfa[.]com | Cluster hostname impersonating Turkmenistan's Ministry of Foreign Affairs. |
| HOSTNAME | www[.]tmgaz-server[.]com | Cluster hostname associated with impersonation of Türkmengaz. |
| HOSTNAME | www[.]tojiktelecomtj[.]com | Cluster hostname impersonating Tojiktelecom. |
| HOSTNAME | www[.]wordcheck[.]info | Hostname listed for a SpiceRAT cluster server presenting the spoofed railway certificate. |
| IPV4 | 171[.]22[.]16[.]187 | SpiceRAT cluster server also observed presenting the spoofed railway certificate. |
| IPV4 | 185[.]122[.]185[.]36 | SpiceRAT server previously resolved by a cluster hostname. |
| IPV4 | 185[.]243[.]112[.]220 | Historical host in the enumerated communications-themed cluster infrastructure. |
| IPV4 | 185[.]243[.]112[.]253 | Host of a cluster-linked subdomain flagged by Hunt.io's SpiceRAT detection. |
| IPV4 | 185[.]243[.]114[.]124 | Cluster host serving the cloned RTX page and an impersonating domain. |
| IPV4 | 185[.]243[.]114[.]238 | Cluster host sharing a self-signed certificate with another cluster server and resolving to an impersonating domain. |
| IPV4 | 185[.]253[.]116[.]145 | Historical host in the enumerated tdtu[.]org infrastructure. |
| IPV4 | 185[.]253[.]117[.]32 | Host in the enumerated government-themed cluster infrastructure. |
| IPV4 | 188[.]190[.]18[.]208 | Cluster host serving the cloned RTX page and presenting shared TLS certificates. |
| IPV4 | 188[.]190[.]29[.]126 | Hunt.io-detected SpiceRAT server that also served the cloned RTX page. |
| IPV4 | 188[.]243[.]115[.]156 | Cluster host serving the cloned RTX page. |
| IPV4 | 192[.]121[.]87[.]172 | Host listed with a Kyrgyzstan government-themed domain. |
| IPV4 | 193[.]29[.]56[.]119 | Host presenting the spoofed Uzbekistan railway TLS certificate. |
| IPV4 | 193[.]29[.]57[.]159 | Cluster host presenting a certificate for a possibly impersonating communications domain. |
| IPV4 | 193[.]29[.]57[.]182 | Host presenting the spoofed Uzbekistan railway TLS certificate. |
| IPV4 | 193[.]29[.]58[.]192 | Host resolving to a domain whose sibling hostname Bitdefender attributed to NodeEdgeRAT. |
| IPV4 | 193[.]29[.]58[.]217 | Host listed with a Kyrgyzstan government-themed domain. |
| IPV4 | 193[.]29[.]59[.]159 | Hunt.io-detected SpiceRAT cluster server. |
| IPV4 | 193[.]29[.]59[.]248 | Historical host in the enumerated tdtu[.]org infrastructure. |
| IPV4 | 194[.]14[.]217[.]119 | Server previously resolved by a Bitdefender-listed SpiceRAT hostname. |
| IPV4 | 194[.]14[.]217[.]199 | Host in the enumerated infocomkg[.]org infrastructure. |
| IPV4 | 194[.]68[.]225[.]168 | Server previously resolved by a Bitdefender-listed SpiceRAT hostname. |
| IPV4 | 194[.]68[.]44[.]133 | Bitdefender-reported SpiceRAT server serving the cloned RTX page. |
| IPV4 | 194[.]71[.]107[.]243 | SpiceRAT server previously resolved by a cluster hostname. |
| IPV4 | 195[.]88[.]191[.]250 | Host listed with a Turkmen energy-themed domain. |
| IPV4 | 195[.]88[.]191[.]70 | Host listed with a domain impersonating the Kyrgyzstan president's residence. |
| IPV4 | 2[.]58[.]14[.]95 | Hunt.io-detected SpiceRAT server serving the cloned RTX page and presenting the spoofed railway certificate. |
| IPV4 | 2[.]58[.]15[.]101 | Historical host in the enumerated government-themed cluster infrastructure. |
| IPV4 | 2[.]58[.]15[.]129 | Host in the enumerated hpsupporter[.]com infrastructure. |
| IPV4 | 2[.]58[.]15[.]172 | Cluster host serving the cloned RTX page. |
| IPV4 | 31[.]57[.]92[.]84 | Cluster host serving the cloned RTX page. |
| IPV4 | 31[.]58[.]209[.]28 | Cluster host serving the cloned RTX page. |
| IPV4 | 31[.]58[.]220[.]250 | Hunt.io-detected SpiceRAT cluster server. |
| IPV4 | 31[.]59[.]185[.]224 | Cluster host serving the cloned RTX page. |
| IPV4 | 45[.]153[.]125[.]20 | Bitdefender-reported SpiceRAT server serving the cloned RTX page and presenting the spoofed railway certificate. |
| IPV4 | 45[.]153[.]125[.]200 | Bitdefender-reported SpiceRAT server serving the cloned RTX page. |
| IPV4 | 45[.]153[.]127[.]186 | Cluster host resolving to a Kazakh government-themed domain. |
| IPV4 | 45[.]153[.]127[.]38 | Host listed with an Uzbekistan government-themed domain. |
| IPV4 | 45[.]153[.]127[.]99 | Cluster-linked host exposing high-port RDP-over-TLS and resolving to government-themed domains. |
| IPV4 | 45[.]67[.]230[.]185 | Historical host in the enumerated communications-themed cluster infrastructure. |
| IPV4 | 45[.]86[.]162[.]141 | Cluster-linked host exposing high-port RDP-over-TLS. |
| IPV4 | 45[.]86[.]162[.]249 | Host in the enumerated hpsupporter[.]com infrastructure. |
| IPV4 | 45[.]86[.]163[.]87 | Host in the enumerated government-themed cluster infrastructure. |
| IPV4 | 46[.]30[.]188[.]54 | Cluster host serving the cloned RTX page under an impersonating telecommunications domain. |
| IPV4 | 46[.]30[.]189[.]191 | Cluster host with a TLC-issued certificate for a government-themed typosquat. |
| IPV4 | 46[.]30[.]190[.]170 | Host in the enumerated communications-themed cluster infrastructure. |
| IPV4 | 46[.]30[.]191[.]214 | Host in the enumerated government-themed cluster infrastructure. |
| IPV4 | 46[.]30[.]191[.]230 | Hunt.io-detected SpiceRAT cluster server. |
| IPV4 | 46[.]30[.]191[.]232 | Host listed among servers impersonating Central Asian entities. |
| IPV4 | 46[.]30[.]191[.]90 | Host in the enumerated hpsupporter[.]com infrastructure. |
| IPV4 | 5[.]183[.]95[.]49 | Host listed with an Uzbekistan government-themed domain. |
| IPV4 | 5[.]183[.]95[.]76 | Cluster-linked host exposing high-port RDP-over-TLS. |
| IPV4 | 83[.]242[.]96[.]242 | Host in the enumerated infocomkg[.]org infrastructure. |
| IPV4 | 91[.]132[.]94[.]36 | Host of a domain impersonating Turkmenistan's Galkynysh gas field. |
| IPV4 | 92[.]243[.]66[.]71 | Host presenting the spoofed Uzbekistan railway TLS certificate. |
| SHA1 | 9297d5fd21ef21b16f5880cd4faea2ad1fb9ee39 | SHA-1 fingerprint listed for the spoofed Uzbekistan railway TLS certificate. |
| SHA256 | 27e072b92b5ac9e3e2a6770bef3e84bdf864b0611d3bc9caca12be2b1a63dae4 | Fingerprint of the spoofed Uzbekistan railway TLS certificate deployed across cluster hosts. |
| SHA256 | e9d0e8b8a33858a7a5a46f78d7a78f9aa7f9b029348d9b618c6a6a1937a39382 | Hash of the cloned RTX homepage used to identify 13 servers in the infrastructure cluster. |
MITRE ATT&CK
T1036.005 · Match Legitimate Resource Name or LocationAttacker-controlled domains and certificates impersonated named Central Asian government bodies and state enterprises.T1071.001 · Web ProtocolsThe article reports that SpiceRAT's command channel operated on port 443, separate from the decoy webpage on port 80.T1583.001 · DomainsThe cluster used registered domains and subdomains for its command-and-control and impersonation infrastructure.
People
Threat Actors
FamousSparrowSuspected China-nexus actor cited because Bitdefender noted overlaps with its previously documented activity; this article does not attribute the investigated servers to it.IndigoZebraSuspected China-nexus actor whose previously reported Central Asian targeting and domain patterns are compared with this cluster; the article also refers to it as Speccom.SpeccomESET's name for IndigoZebra, whose historical infrastructure is compared with this cluster; the article does not establish that it operated the investigated servers.
Malware
BloodAlchemyThe impersonation of Uzbekistan railway also appears in Bitdefender's BloodAlchemy C2 domain, and in the certificate observed on Hunt.io's SpiceRAT servers.NodeEdgeRATan identical TLS certificate connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of the seven malware families documented in the SilkParasite report.NomadRATcertificate connect this infrastructure to hosts Bitdefender attributed to SpiceRAT, NodeEdgeRAT, and NomadRAT, three of the seven malware families documented in the SilkParasite report.SpiceRATThis research was carried out jointly with researcher Guy Yasur. Together, we tracked a cluster of SpiceRAT command and control servers active from late 2025 through August 2026 across a small subset of European hosting
Vendors
CrownCloudstorage.natcommunzu[.]com, was hosted on 185.243.112[.]253, an Access2.IT server resold through CrownCloud not previously seen in this group of servers, and flagged by Hunt.io's SpiceRAT detection in late 2025.EDIS GmbHNamecheap185.243.114[.]238 resolved to a single domain, normativ.dushanbeidc[.]org, a NameCheap-registered domain impersonating Tajikistan's national IT-hub project. The domain registrar, hosting provider and country targetingTLCThe certificate imitating the Uzbekistan railway entity was issued by TLC, a certificate authority wholly funded by CAICT, a Chinese state research institute under the Ministry of Industry and Information Technology.
Tools
Countries
Bulgariain three different countries: 185.122.185[.]36 in Estonia on 24 January 2026, 194.71.107[.]243 in Bulgaria on 30 January, and 188.190.29[.]126 on 26 February, and where it currently resolves as of this post'sChina¬å¸ (TL Certification Center, TLC). TLC is wholly funded by the China Academy of Information and Communications Technology (CAICT), a research institute under China's Ministry of Industry and Information Technology.Estoniaresolved to three SpiceRAT servers in three different countries: 185.122.185[.]36 in Estonia on 24 January 2026, 194.71.107[.]243 in Bulgaria on 30 January, and 188.190.29[.]126 on 26 February, andGermanyAn identical certificate (matched by SHA-256) appeared on 185.243.114[.]238 (AS48314, IP-Projects, Germany) between 28 and 31 July. A HuntSQL query on the organization value confirmed the certificate appeared onKazakhstanKyrgyzstanUzbekistan government administration (azure.adm-devon[.]com), and the residence of the Kyrgyzstan president (data.yntymak-ordo[.]com) were identified on the same infrastructure profile. Full domain andTajikistanresolved to a single domain, normativ.dushanbeidc[.]org, a NameCheap-registered domain impersonating Tajikistan's national IT-hub project. The domain registrar, hosting provider and country targeting align with theTurkmenistanIdentified domains spoof named entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs.Uzbekistanby a Chinese state-affiliated certificate authority associated with the infrastructure impersonates Uzbekistan's state railway authority. Additionally, this cluster also shares registration-level relationships with
Industries
EnergyTargeting Across Central Asia's Government and Energy SectorsGovernmentobtained from a Chinese CA whose public presence is domestic and whose support channels run through a government affiliated institute. The selection of TLC suggests a deliberate one and an operator with access to aTelecommunicationstojiktelecomtj[.]com on 46.30.188[.]54 targets Tojiktelecom, Tajikistan's state telecommunications provider.