Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
5 malware families

SilverFox

Also known asSilverFox

SilverFox is a Chinese-origin, Chinese-speaking threat actor associated with ValleyRAT/Winos 4.0 and related Gh0stRAT-family tooling. Reporting in the provided content describes SilverFox targeting primarily Chinese-speaking users in mainland China and the broader region through social engineering and trojanized software, with additional targeting of Taiwan and Japan. Observed lures include fake Microsoft Teams installers, trojanized legitimate software such as Arma 3 server binaries and WeChat-themed bundles, fake censorship-bypass tools, HR and disciplinary-investigation documents, banking fraud guidance, meeting-room reservation apps, Telegram installers, Doubao AI, game cheats, and other Chinese-language decoys. Across the cited reporting, SilverFox is linked to ValleyRAT, Winos 4.0, HoldingHands RAT (also known as Gh0stBins), Gh0stCringe RAT, Ghost RAT, and RustyStealer. One source also notes the alias YouSnake. The content repeatedly links SilverFox activity to the broader Winos/Gh0stRAT-derived malware ecosystem. Tactics and techniques directly described in the content include DLL sideloading using legitimate Tencent binaries such as GameBox.exe and UxEnhanceHost, use of NSIS and WinRAR SFX droppers, staged in-memory decryption and reflective loading, process injection and hollowing, scheduled-task and service-based persistence, registry-based persistence indicators, Windows Defender exclusions, anti-debugging and anti-VM checks, API hashing, clipboard theft, keylogging, active-window monitoring, downloader functionality, and exfiltration of collected data. Multiple reports describe SilverFox using BYOVD to terminate or evade security tools, including exploitation of the STProcessMonitor kernel driver for privilege escalation. One report states the group also used compromised PHP servers exposed to remote code execution to install ValleyRAT via msiexec. Infrastructure described in the content includes command-and-control and staging hosted across Tencent Cloud, Alibaba Cloud, AWS Hong Kong and Singapore, Vultr Singapore, Fastmos Hong Kong, SonderCloud, Cloudbays, Huawei Cloud, SpeedVM/LeaseKVM, ANTBOX Networks, Amazon S3, and bare-IP VPS infrastructure. Several reports highlight an apparent shift in some ValleyRAT activity from historically Tencent Cloud-hosted infrastructure to Western VPS providers. The content also notes recurring registrar patterns involving 22.cn, Gname.com, and NameSilo, and repeated WHOIS artifacts including the name Peng Benbo and email di823748@163.com in infrastructure linked to SilverFox campaigns. The content characterizes SilverFox as a Chinese-nexus actor; some reporting explicitly calls it China-based or Chinese-origin, and one cited source describes it as a suspected financially motivated threat actor with infrastructure inside and targeting China.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Health Care Equipment & Services
MITRE ATT&CK

Tradecraft

60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics89 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.001
Domains
T1608
Stage Capabilities
T1608.006
SEO Poisoning
TA0001
Initial Access
3 techniques
T1189
Drive-by Compromise
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
T1566
Phishing
T1566.001×2
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
7 techniques
T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1106
Native API
T1129×3
Shared Modules
T1197
BITS Jobs
T1204
User Execution
T1204.002×4
Malicious File
TA0003
Persistence
5 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1112
Modify Registry
T1197
BITS Jobs
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
6 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1055×4
Process Injection
T1055.012
Process Hollowing
T1134×2
Access Token Manipulation
T1134.001
Token Impersonation/Theft
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
13 techniques
T1014×2
Rootkit
T1027×5
Obfuscated Files or Information
T1027.002×2
Software Packing
T1027.007
Dynamic API Resolution
T1027.013
Encrypted/Encoded File
T1036×2
Masquerading
T1036.005×3
Match Legitimate Resource Name or Location
T1055×4
Process Injection
T1055.012
Process Hollowing
T1070
Indicator Removal
T1070.004×2
File Deletion
T1134×2
Access Token Manipulation
T1134.001
Token Impersonation/Theft
T1140×3
Deobfuscate/Decode Files or Information
T1197
BITS Jobs
T1218
System Binary Proxy Execution
T1218.011
Rundll32
T1497×3
Virtualization/Sandbox Evasion
T1497.001×3
System Checks
T1564
Hide Artifacts
T1564.001
Hidden Files and Directories
T1620
Reflective Code Loading
T1622×3
Debugger Evasion
TA0112
Defense Impairment
2 techniques
T1112
Modify Registry
T1222
File and Directory Permissions Modification
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0007
Discovery
6 techniques
T1057×4
Process Discovery
T1082×2
System Information Discovery
T1083×2
File and Directory Discovery
T1497×3
Virtualization/Sandbox Evasion
T1497.001×3
System Checks
T1614
System Location Discovery
T1622×3
Debugger Evasion
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.003
Distributed Component Object Model
TA0009
Collection
2 techniques
T1115
Clipboard Data
T1560
Archive Collected Data
TA0011
Command and Control
7 techniques
T1071×3
Application Layer Protocol
T1071.001
Web Protocols
T1095
Non-Application Layer Protocol
T1104
Multi-Stage Channels
T1105
Ingress Tool Transfer
T1219
Remote Access Tools
T1571×2
Non-Standard Port
T1573
Encrypted Channel
T1573.001
Symmetric Cryptography
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
IOCS

Observables

163 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

derp ca blogNews
Jun 21, 2026
SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor | Derp

A SilverFox-aligned loader chain wrapped in a trojanized Panasonic host that reconstructs Alibaba OSS staging URLs, retrieves image-named encrypted carriers, uses signed side-loading, RPC scheduled-task creation, AV/Defender evasion and prep, and ultimately deploys a backdoor stage via rundll32.dat!Edge/Sauron behavior.

Read more
security online infoNews
May 24, 2026
ValleyRAT Malware Campaign Exploits Teams Users

Linked to a ValleyRAT campaign targeting corporate users with trojanized software bundles disguised as Microsoft Teams installers, using social engineering, DLL sideloading, PowerShell-based Windows Defender exclusions, in-memory shellcode execution, and information theft.

Read more
k7 labsNews
May 20, 2026
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading - K7 Labs

Operating a malware campaign using fake Microsoft Teams download sites to deliver a trojanized installer that deploys a ValleyRAT variant through DLL sideloading, staged in-memory decryption, persistence, and data theft.

Read more
breakglass intelNews
Apr 3, 2026
Operation MIRZBOW - LNK Dropper Campaign Targeting Arabic-Speaking Users - Breakglass Intelligence - Breakglass Intelligence

Referenced as a Chinese-origin infostealer/RAT family associated with trojanized software and possibly linked to the final payload in this campaign, but not explicitly identified as the operator of the campaign.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping60

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables163

Domains, IPs, and hashes tied to this actor, refreshed continuously.