Sainbox RAT is a remote access trojan described as a variant of Gh0st RAT/Gh0stRAT. Proofpoint reported renewed activity involving Sainbox beginning in 2023 after years of low visibility, and notes that third-party researchers also refer to it as FatalRAT. The malware has been delivered in multiple email-driven campaigns using Chinese-language business lures such as invoices, payments, and product themes, as well as at least one Japanese-language invoice lure targeting organizations in Japan. Observed delivery methods include emails containing URLs to compressed executables, and Excel or PDF attachments containing URLs that lead to zipped payloads. In one 17 May 2023 campaign targeting dozens of companies, mainly in the manufacturing and technology sectors, emails spoofed an invoicing sender and linked to a zipped executable named 26866498.exe that installed Sainbox; the sample used C2 fakaka16[.]top:3366. Proofpoint observed nearly 10 Sainbox campaigns using C2 domains containing variations of "fakaka," often with sequential numbering, with several such domains registered via Jiangsu Bangning Science & Technology Co. Ltd. Additional reporting describes Silver Fox (aka Void Arachne) distributing Sainbox RAT and the open-source Hidden rootkit through fake software websites advertising WPS Office, Sogou, and DeepSeek, targeting Chinese-speaking Windows users. In that activity, malicious Chinese-language MSI installers launched a legitimate executable, shine.exe, which sideloaded a rogue libcef.dll; the rogue DLL extracted shellcode from 1.txt and executed another DLL payload identified as Sainbox RAT. The payload’s .data section reportedly contained a PE binary that may be executed as a rootkit driver, and the accompanying Hidden rootkit was used to hide malware-related processes and Windows Registry keys. High-confidence capabilities directly attributed to Sainbox in the provided content include downloading additional payloads and stealing data from compromised hosts. The malware is associated in reporting with Chinese-themed cybercrime activity and with campaigns attributed to Silver Fox/Void Arachne.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another Gh0st-family RAT sharing the same stock panel default config strings seen in the recovered implant.
Remote access trojan delivered via fake software sites in a campaign attributed to Silver Fox; paired with a rootkit for stealth/persistence.
Remote access trojan (RAT) that is a variant of Gh0st RAT, used to download additional payloads and steal data from compromised hosts.
Gh0stRAT-derived commodity RAT variant distributed via low-volume Chinese-language email campaigns (commonly invoice-themed) using URLs or Excel attachments containing URLs that lead to zipped executables. Observed C2 infrastructure includes domains with 'fakaka' patterns (e.g., fakaka16[.]top:3366).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.