Silver Fox, also known as Yinhu (银狐), is a Chinese threat cluster associated with deceptive software-download campaigns targeting Chinese-speaking users and China-based operations. Microsoft has assessed with moderate confidence that observed counterfeit-software campaigns are consistent with Silver Fox, while not attributing the actor to a nation state. The group has a record of using high-fidelity spoofed vendor download pages and malicious installers to distribute remote-access malware, including Gh0st RAT and ValleyRAT (also known as Winos 4.0). Silver Fox-linked activity has affected organizations in health care, manufacturing, gaming, technology, logistics, government, and education. Operators use counterfeit installers, and reporting also associates the cluster with spear-phishing through instant-messaging platforms. Observed tradecraft includes malicious-file execution, abuse of Windows Installer, scheduled-task persistence, DLL sideloading through signed applications, process injection, attempted SMB lateral movement, and deployment of additional payloads. Campaigns associated with the cluster tamper with endpoint defenses by creating security-product exclusions, disabling or impairing Windows Update, modifying access controls to hinder payload removal, and deleting volume shadow copies. ValleyRAT activity likely linked to Silver Fox has used trojanized legitimate Chinese software to obtain trusted-process execution through DLL sideloading. The backdoor supports system reconnaissance, keystroke and clipboard collection, screenshot capture, log clearing, remote module delivery, process hollowing, and data exfiltration. Attribution of individual ValleyRAT campaigns based solely on use of the malware family is not definitive because it is used by multiple actors. Void Arachne is a separate threat actor and is not an alias of Silver Fox.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NsecSoft NSecKrnl driver, identified as CVE-2025-68947, is a signed kernel-mode driver that exposes functionality for arbitrary process termination. By exploiting this capability, the ransomware is able to terminate the processes of major EDR and antivirus products...
CVE-2023-52271 documents how an affected version of wsftprm.sys can be abused to terminate protected processes.
865 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a malware-distribution campaign through high-fidelity counterfeit software-download sites targeting China-based operations of multinational organizations and Chinese-speaking users. The campaign deploys remote-access malware, establishes persistence, disables or weakens security controls and Windows Update, and communicates with attacker-controlled C2 infrastructure. The group is described as motivated by cyber espionage and financial gain.
Conducting a counterfeit-software-installer campaign against Windows systems. The operation uses cloned software-vendor download pages and per-request rebuilt ZIP archives to deliver payloads, establish persistence, impair Microsoft Defender and Windows Update protections, hinder recovery, and communicate with attacker-controlled command-and-control infrastructure.
Likely conducted a ValleyRAT distribution campaign by disguising the backdoor within a modified, signed QN Wallpaper adware application. The campaign predominantly affected users in China and India.
Conducting a deceptive software-download campaign that uses counterfeit vendor websites and dynamically generated malicious installer archives to compromise primarily China-based and Chinese-speaking users. The campaign establishes scheduled-task persistence, creates SYSTEM tasks to weaken Microsoft Defender, disables Windows Update and shadow copies, injects into processes, uses cloud object storage for staging, and communicates with C2 infrastructure over non-standard ports.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.