Silver Fox is a Chinese-speaking, China-linked threat cluster associated primarily with cybercrime activity, though some reporting has described parts of its ecosystem as state-associated or overlapping with espionage-oriented tradecraft. The actor is also tracked under aliases including Void Arachne, SwimSnake, and SilverFox APT, although some alias relationships remain disputed. Silver Fox has been active since at least 2022 and is best known for repeated use of ValleyRAT, also called Winos 4.0, alongside an expanding malware ecosystem that has included SafeRat, ABCDoor, MODBEACON, and campaigns with possible but not always conclusive links to Atlas RAT, RomulusLoader, and SilentRunLoader. The group commonly relies on phishing, fake software installers, typosquatted download sites, and ZIP-based delivery chains to obtain initial access. Observed lures have impersonated tax authorities, invoices, payroll or HR themes, and popular software brands. Silver Fox frequently abuses DLL sideloading with legitimate signed executables, reflective or in-memory loading, staged shellcode execution, and process injection to deploy payloads while reducing on-disk visibility. A defining feature of Silver Fox operations is aggressive defense evasion. The actor has repeatedly used bring-your-own-vulnerable-driver techniques and signed or vulnerable kernel drivers to disable or degrade security tooling, terminate defensive processes, and gain kernel-level capabilities. Reporting also describes NTDLL unhooking, dynamic API resolution, anti-analysis checks, AMSI bypass in some malware families, and layered recovery mechanisms such as watchdog components and scheduled-task persistence. Several campaigns show modular design, registry- or image-based payload concealment, and resilient multi-stage execution chains. Silver Fox malware supports persistent remote access, command execution, file transfer, host fingerprinting, plugin loading, keylogging, screen capture or streaming, credential theft in some cases, and broader post-compromise activity. ValleyRAT-linked activity has also included clipboard hijacking for cryptocurrency theft and theft of messaging-application data. SafeRat has been observed interfering with antivirus products and stealing remote-management credentials. ABCDoor added Python-based backdoor functionality including keylogging, file operations, clipboard access, self-update, and multi-screen monitoring. MODBEACON reflects continued investment in modular, memory-resident Rust tooling. Victimology indicates a strong focus on Asia, especially Chinese- and Japanese-speaking targets, but operations have also targeted Russia and India. Confirmed or reported targets include industrial manufacturing, technology, education, state-owned enterprises, consulting, trade, transport, and other organizations reached through tax- and invoice-themed social engineering. Multiple campaigns specifically targeted Chinese-speaking users with counterfeit installers, Japanese industrial organizations with BYOVD-enabled ValleyRAT intrusions, Russian organizations with tax-themed phishing delivering ValleyRAT and ABCDoor, and Indian tax-related targets in activity assessed as overlapping with the broader Silver Fox ecosystem. Overall, Silver Fox represents a prolific China-linked intrusion ecosystem centered on scalable malware distribution, durable remote access, and strong evasion engineering, with recurring use of ValleyRAT/Winos 4.0 as a core operational component.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NsecSoft NSecKrnl driver, identified as CVE-2025-68947, is a signed kernel-mode driver that exposes functionality for arbitrary process termination. By exploiting this capability, the ransomware is able to terminate the processes of major EDR and antivirus products...
CVE-2023-52271 documents how an affected version of wsftprm.sys can be abused to terminate protected processes.
750 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a separate actor tied to overlapping infrastructure fingerprints; the report explicitly states there is no evidence of coordination or attribution linkage to the main campaign.
Conducting BYOVD-enabled intrusion activity against a Japanese industrial manufacturing target to deploy ValleyRAT for persistent remote access and defense evasion.
Conducting BYOVD-enabled intrusion campaigns against industrial manufacturing targets in Japan, using phishing lures, DLL sideloading, defense evasion, persistence, and ValleyRAT for remote access.
Assessed as the likely operator or user of SafeRat in phishing campaigns using DLL sideloading loaders, with links to prior Silver Fox tooling and tradecraft including ValleyRat, AtlasRat, DonutLoader, and UUIDLoader. Campaigns used tax/invoice-themed ZIP lures, targeted victims in Asia, and included silent deployment of SunLogin RMM.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.