Skip to content

SpiceRAT

SpiceRAT is a Windows remote-access trojan used in targeted cyberespionage activity.

Profile source: Mallory opens in a new tab

SpiceRAT

Family profile

SpiceRAT is a Windows remote-access trojan used in targeted cyberespionage activity. Cisco Talos previously associated it with the suspected China-based SneakyChef group, and it was later observed as one of several remote-access tools used in the SilkParasite campaign, a medium-confidence China-nexus activity cluster targeting government organizations in Central Asia. SilkParasite activity also targeted government, energy, and telecommunications interests in the region. Infection chains used spear-phishing messages carrying malicious Microsoft Office documents, including password-protected archives, and executed payloads through DLL sideloading with legitimate signed Windows applications. SpiceRAT has been documented establishing scheduled-task persistence and supports downloading and executing binaries and arbitrary commands. Its command-and-control infrastructure has been linked through shared domains, certificates, and hosting artifacts with infrastructure associated with other SilkParasite RATs, although this infrastructure overlap does not establish common operator control.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 18, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • BG1
  • NL1

Leading providers

  • EDIS GmbH1
  • GWY IT PTY LTD1

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

2 named in public reporting
SilkParasite

Hunt.io identified a cluster of five active SpiceRAT command-and-control servers in mid-March 2026 and linked them through common hostnames, TLS certificates, and a cloned RTX Corporation webpage.

SneakyChef

The initial foothold involved two families, SpiceRAT and DriveSilkRAT... SpiceRAT is the family that was previously documented by Cisco Talos, June 2024, in reporting on SneakyChef.

MITRE ATT&CK

SpiceRAT in ATT&CK

20 distinct techniques

Reporting

Research mentioning SpiceRAT

Aug 19
Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.

Aug 19
Malware News

SilkParasite: Tracking a China-Nexus APT Across Central Asia - Malware News - Malware Analysis, News and Indicators

Aug 19
The Hacker News

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.