SilverFox, also known as Yinhu, is a Windows-focused remote-access Trojan ecosystem used in campaigns primarily targeting Chinese-speaking users and organizations. Operations have used spoofed software-download websites, SEO poisoning and watering-hole delivery, and instant-messaging spearphishing to distribute malware masquerading as legitimate software installers or business-themed documents. The activity has impersonated widely used productivity, remote-access, browser, security, and communications products.
SilverFox-related payloads employ DLL side-loading, staged in-memory payload execution, process injection and process hollowing, anti-debugging and virtual-machine evasion, code and configuration obfuscation, and security-tool impairment. Observed functions include host, process, file, and directory discovery; credential and email collection; keylogging; screen and clipboard capture; persistence through startup mechanisms, scheduled tasks, and services; and command-and-control-based data exfiltration. Some variants use RPC-based command-and-control communications and encrypted payloads or configuration data.
SilverFox activity has been associated with ValleyRAT, Winos 4.0, Gh0stRAT-derived tooling, HoldingHands, UTG-Q-1000, VoidArachne, and ValleyThief. Public reporting identifies overlap among these tools, but operator-level attribution remains unresolved.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
For twelve operationally-named domains to all land on the same registrant email without privacy — and for that email to be a personal gmail.com address rather than a burner — is an operator OPSEC failure of the kind that normally gets scrubbed before the first phishing sample ever leaves the author's workstation.
ATT&CK IDs: "T1027 - Obfuscated Files or Information"; tags include "Code_Obfuscation."
The name "360news" is a deliberate typosquat of Qihoo 360 (奇虎360), the largest Chinese cybersecurity vendor. Hosting fake "Qihoo 360 Security" download pages under a .icu TLD is low-effort social engineering...
Two suggestive names — jackadmin reads like a C2 admin panel hostname, jackbank reads like a banking trojan overlay / fraud panel hostname — repeated five times each as a pre-provisioned batch for when the previous set gets burned.
Command and Control Ingress Tool Transfer T1105 BitsAdmin/PowerShell downloading payloads
2,080 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive remote-access trojan targeting Chinese organizations and users. It is distributed through spoofed legitimate-software websites and spear-phishing delivered through instant-messaging platforms.
A layered malware chain wrapped in a trojanized Panasonic host that reconstructs Alibaba OSS staging URLs, retrieves image-named encrypted carriers, performs signed DLL side-loading, uses RPC task scheduling, deploys AV-evasion/preparation logic, and ultimately reaches a late-stage backdoor component.
SilverFox is described as a Chinese-origin infostealer/RAT associated with trojanized software. In this campaign, the final trojanized chrome.exe payload may be a SilverFox variant.
A SilverFox RAT variant disguised as a Trend Micro Titanium installer. It hides logic inside a custom virtual machine with a binary search tree dispatcher, uses ChaCha20/Salsa20-style encryption for code and C2 payloads, performs anti-debugging and anti-VM checks, decrypts code in memory, injects into processes, and communicates with operators over Windows MSRPC using NdrAsyncClientCall.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.