SPICERAT
SPICERATSpiceRAT
Description
SpiceRAT is a remote access trojan first reported by Cisco Talos in June 2024, in a campaign attributed to SneakyChef targeting government agencies and think tanks in EMEA and Asia. It is delivered through two chains, one using a LNK file and one using an HTA, both loading the implant by DLL sideloading through a renamed legitimate executable; Talos names the loader component HelpLoader. Bitdefender observed SpiceRAT again in August 2026 as part of the SilkParasite activity cluster in Central Asia, alongside implants of that cluster's own.