Last seven days
- First activity
- Sep 18, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
SpiceRAT is a Windows remote-access trojan used in targeted cyberespionage activity.
Profile source: Mallory opens in a new tabSpiceRAT
SpiceRAT is a Windows remote-access trojan used in targeted cyberespionage activity. Cisco Talos previously associated it with the suspected China-based SneakyChef group, and it was later observed as one of several remote-access tools used in the SilkParasite campaign, a medium-confidence China-nexus activity cluster targeting government organizations in Central Asia. SilkParasite activity also targeted government, energy, and telecommunications interests in the region. Infection chains used spear-phishing messages carrying malicious Microsoft Office documents, including password-protected archives, and executed payloads through DLL sideloading with legitimate signed Windows applications. SpiceRAT has been documented establishing scheduled-task persistence and supports downloading and executing binaries and arbitrary commands. Its command-and-control infrastructure has been linked through shared domains, certificates, and hosting artifacts with infrastructure associated with other SilkParasite RATs, although this infrastructure overlap does not establish common operator control.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Hunt.io identified a cluster of five active SpiceRAT command-and-control servers in mid-March 2026 and linked them through common hostnames, TLS certificates, and a cloned RTX Corporation webpage.
The initial foothold involved two families, SpiceRAT and DriveSilkRAT... SpiceRAT is the family that was previously documented by Cisco Talos, June 2024, in reporting on SneakyChef.
MITRE ATT&CK
Reporting
A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.