SPICERAT

SPICERATSpiceRAT

Description

SpiceRAT is a remote access trojan first reported by Cisco Talos in June 2024, in a campaign attributed to SneakyChef targeting government agencies and think tanks in EMEA and Asia. It is delivered through two chains, one using a LNK file and one using an HTA, both loading the implant by DLL sideloading through a renamed legitimate executable; Talos names the loader component HelpLoader. Bitdefender observed SpiceRAT again in August 2026 as part of the SilkParasite activity cluster in Central Asia, alongside implants of that cluster's own.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.