Silver Fox is a China-linked threat actor associated with a blend of cybercrime and suspected state-aligned activity, with operations spanning espionage, credential and data theft, and financially motivated intrusions. The group is widely tracked as Silver Fox and has also been referred to as Void Arachne; reporting has additionally linked related or overlapping activity to labels such as TA4922, though such mappings are not universally treated as exact equivalents. Silver Fox is most consistently associated with campaigns across Asia, including Japan, India, Indonesia, Taiwan, and Russia, and has targeted technology companies, educational institutions, state-owned enterprises, healthcare organizations, public-sector entities, finance-related personnel, taxpayers, and corporate accounting teams. The actor is known for heavy use of social engineering and distributor-driven intrusion operations. Common delivery themes include tax notices, salary or HR notifications, invoices, fake software updates, counterfeit download portals, SEO poisoning, trojanized installers, and messaging-platform lures. Silver Fox frequently abuses DLL sideloading with legitimate signed applications, multi-stage loaders, fileless execution, image-based payload concealment, and anti-analysis checks. Observed persistence and defense-evasion behaviors include scheduled tasks, Windows services, registry autoruns, AMSI bypass, Windows Defender exclusions, process injection, log suppression, and use of kernel-mode components or Bring Your Own Vulnerable Driver techniques to disable security tools. Silver Fox maintains a broad and evolving malware ecosystem. Malware and tooling repeatedly associated with the actor include ValleyRAT, also known as Winos 4.0, a Gh0st RAT-derived modular remote access trojan that has become one of the group’s hallmark implants; MODBEACON, a Rust-based modular memory-resident RAT; ABCDoor, a Python/Cython backdoor; Atlas RAT; variants of Gh0st RAT; RomulusLoader; SilentRunLoader; and other loaders and support components. ValleyRAT campaigns have been observed using unusually deep multi-stage chains, steganographic or image-carried payloads, WebSocket, QUIC, and Gh0stKCP-based communications, plugin delivery, clipboard theft, Telegram data theft, and rootkit-backed post-compromise control. MODBEACON has been described as modular, plugin-capable, memory-resident, and delivered through counterfeit domains, malicious archives, and fake installers. ABCDoor supports persistence, screen capture, file and process operations, clipboard theft, and remote input control. Operational reporting indicates Silver Fox often relies on multiple distributors or traffic brokers, suggesting a more complex ecosystem than a single tightly centralized intrusion set. This helps explain the diversity of lures, malware packaging, and victimology seen across campaigns. The actor has repeatedly used tax-themed phishing against organizations and individuals in multiple countries, including India, Russia, and Indonesia, and has also expanded into Japanese-language operations. Some campaigns have impersonated government tax authorities, while others have masqueraded as popular consumer or enterprise software, including translation tools, VPN clients, browser software, collaboration tools, and medical imaging applications. Silver Fox activity has also been linked to signed malicious or abused drivers and kernel-level tradecraft. Reporting has described support or watchdog drivers and rootkit-capable components used to terminate security products, hide malware activity, or maintain resilient access. In some intrusion chains, the actor has used vulnerable or malicious drivers to suppress endpoint protections before deploying user-mode implants. Attribution confidence varies by campaign. Silver Fox is broadly assessed as China-based or China-aligned, and several reports characterize it as a cybercrime group with state-associated or state-tolerated features, reflecting overlap between espionage-oriented targeting and criminal monetization. Some ValleyRAT or related campaigns show infrastructure and tradecraft overlap with Silver Fox but stop short of definitive attribution, so not every use of ValleyRAT or Gh0st-derived tooling should be assumed to be Silver Fox. Even so, the strongest recurring picture is of a prolific Chinese threat actor operating at scale across Asia with adaptable social engineering, modular malware, and a mature delivery ecosystem that spans both cybercrime and intelligence-adjacent objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
28 malware families attributed to this actor across reporting.
23 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
597 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another Chinese cybercrime group that uses Gh0st RAT.
Conducting malware campaigns using the MODBEACON RAT and fake software installers, with SEO poisoning, counterfeit domains, and malicious ZIP archives to target technology, education, and state-owned enterprises across Asia.
Conducting an active malware campaign using the multi-stage ValleyRAT infection chain, including DLL sideloading, steganography, Go-based RAT deployment, antivirus disabling, kernel rootkit installation, data theft, and persistence via polymorphic samples and trojanized installers.
A Chinese cybercrime group linked here through infrastructure and tactical overlaps to a tax-themed phishing campaign targeting Indian taxpayers, tax professionals, and corporate finance teams, with suspected goals of covert access, credential theft, intelligence collection, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.