SilverFox
SilverFox is a Chinese-origin, Chinese-speaking threat actor associated with ValleyRAT/Winos 4.0 and related Gh0stRAT-family tooling. Reporting in the provided content describes SilverFox targeting primarily Chinese-speaking users in mainland China and the broader region through social engineering and trojanized software, with additional targeting of Taiwan and Japan. Observed lures include fake Microsoft Teams installers, trojanized legitimate software such as Arma 3 server binaries and WeChat-themed bundles, fake censorship-bypass tools, HR and disciplinary-investigation documents, banking fraud guidance, meeting-room reservation apps, Telegram installers, Doubao AI, game cheats, and other Chinese-language decoys. Across the cited reporting, SilverFox is linked to ValleyRAT, Winos 4.0, HoldingHands RAT (also known as Gh0stBins), Gh0stCringe RAT, Ghost RAT, and RustyStealer. One source also notes the alias YouSnake. The content repeatedly links SilverFox activity to the broader Winos/Gh0stRAT-derived malware ecosystem. Tactics and techniques directly described in the content include DLL sideloading using legitimate Tencent binaries such as GameBox.exe and UxEnhanceHost, use of NSIS and WinRAR SFX droppers, staged in-memory decryption and reflective loading, process injection and hollowing, scheduled-task and service-based persistence, registry-based persistence indicators, Windows Defender exclusions, anti-debugging and anti-VM checks, API hashing, clipboard theft, keylogging, active-window monitoring, downloader functionality, and exfiltration of collected data. Multiple reports describe SilverFox using BYOVD to terminate or evade security tools, including exploitation of the STProcessMonitor kernel driver for privilege escalation. One report states the group also used compromised PHP servers exposed to remote code execution to install ValleyRAT via msiexec. Infrastructure described in the content includes command-and-control and staging hosted across Tencent Cloud, Alibaba Cloud, AWS Hong Kong and Singapore, Vultr Singapore, Fastmos Hong Kong, SonderCloud, Cloudbays, Huawei Cloud, SpeedVM/LeaseKVM, ANTBOX Networks, Amazon S3, and bare-IP VPS infrastructure. Several reports highlight an apparent shift in some ValleyRAT activity from historically Tencent Cloud-hosted infrastructure to Western VPS providers. The content also notes recurring registrar patterns involving 22.cn, Gname.com, and NameSilo, and repeated WHOIS artifacts including the name Peng Benbo and email di823748@163.com in infrastructure linked to SilverFox campaigns. The content characterizes SilverFox as a Chinese-nexus actor; some reporting explicitly calls it China-based or Chinese-origin, and one cited source describes it as a suspected financially motivated threat actor with infrastructure inside and targeting China.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
- Health Care Equipment & Services
Tradecraft
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
163 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SilverFox-aligned loader chain wrapped in a trojanized Panasonic host that reconstructs Alibaba OSS staging URLs, retrieves image-named encrypted carriers, uses signed side-loading, RPC scheduled-task creation, AV/Defender evasion and prep, and ultimately deploys a backdoor stage via rundll32.dat!Edge/Sauron behavior.
Linked to a ValleyRAT campaign targeting corporate users with trojanized software bundles disguised as Microsoft Teams installers, using social engineering, DLL sideloading, PowerShell-based Windows Defender exclusions, in-memory shellcode execution, and information theft.
Operating a malware campaign using fake Microsoft Teams download sites to deliver a trojanized installer that deploys a ValleyRAT variant through DLL sideloading, staged in-memory decryption, persistence, and data theft.
Referenced as a Chinese-origin infostealer/RAT family associated with trojanized software and possibly linked to the final payload in this campaign, but not explicitly identified as the operator of the campaign.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.