Silver Fox is a China-nexus threat actor active since at least 2022, also known as SilverFox, Yinhu (银狐), Void Arachne, SwimSnake, UTG-Q-1000, and Valley Thief. Its operations involve remote-access malware, data theft, surveillance, and financially motivated cybercrime; no confirmed nation-state attribution has been established. Targets include Chinese organizations and users, China-based operations of multinational companies, Indian users, and a Japanese industrial manufacturer. Affected sectors include manufacturing, healthcare and medical devices, technology, gaming, logistics, government, and higher education. Silver Fox obtains initial access through counterfeit software-download websites, trojanized installers, and phishing, including invoice-themed email and instant-messaging lures. It is closely associated with ValleyRAT and has also distributed Gh0st RAT. Its execution chains abuse legitimate, digitally signed applications for DLL sideloading and use encrypted payloads, in-memory execution, thread-context hijacking, and process hollowing. Remote-access payloads support command execution, keylogging, screenshots, clipboard collection, host discovery, data exfiltration, and deployment of additional modules. A distinguishing feature is the use of signed vulnerable or abusable kernel drivers to terminate antivirus and endpoint-security processes, including protected processes. Modular loaders support alternative drivers, anti-analysis checks, and removal of user-mode API hooks. Persistence combines scheduled tasks, Registry-based mechanisms, Startup entries, and watchdog routines that restore interrupted loaders or injected payloads. Other observed behaviors include security-policy tampering, disabling Windows Update, deleting shadow copies, and attempted lateral movement through SMB administrative shares. Shared malware or infrastructure alone does not establish that another campaign belongs to Silver Fox.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Driver file wsftprm.sys — Vulnerable signed driver associated with CVE-2023-52271. The campaign uses vulnerable signed kernel drivers to terminate protected antivirus and endpoint-security processes.
The NsecSoft NSecKrnl driver, identified as CVE-2025-68947, is a signed kernel-mode driver that exposes functionality for arbitrary process termination. By exploiting this capability, the ransomware is able to terminate the processes of major EDR and antivirus products...
898 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducts cyberespionage using all-in-one loaders that disable endpoint defenses before deploying the ValleyRAT backdoor. The reported campaign abuses Microsoft-signed WatchDog/Zemana-based security drivers to terminate antivirus and EDR processes, including protected processes. Updated samples reportedly modify an unauthenticated Authenticode timestamp byte to change driver hashes while retaining a valid signature.
Distributing a malicious installer masquerading as KakaoTalk through SEO-poisoning redirects, while changing installer packaging among NSIS, Advanced Installer, and Inno Setup.
Suspected of distributing trojanized KakaoTalk installers through SEO poisoning and fake download sites. The campaign used changing installer packaging, patched signed legitimate files, DLL side-loading, shellcode loaders, encrypted PNG steganography, service persistence, and C2-delivered payloads.
A referenced ecosystem whose trusted-software abuse and tax-lure tradecraft resembles PAPERMILL activity; the content explicitly cautions that this does not establish attribution to Silver Fox.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.