Silver Fox is a Chinese-language malware and cybercrime ecosystem active since at least 2022 that commonly distributes modular Windows remote-access trojans through phishing websites, counterfeit software installers, fake update prompts, email, and instant-messaging lures. Campaigns associated with the name frequently impersonate popular software and online services, including translation tools, office software, browsers, VPN clients, and Flash updates, and use fake download pages and search-engine optimization to drive victim installation.
Silver Fox activity is strongly associated with the Winos trojan family and related modular RAT variants. In observed infection chains, installer packages deploy staged components that load attacker-specified files, execute shellcode in memory, establish persistence through Windows autorun mechanisms, and launch a final remote-access payload. Reported capabilities across Silver Fox-linked malware include remote control, modular plugin execution, keylogging, screenshot capture, clipboard theft, data theft, and broader post-compromise host control. Some related samples also show in-memory multi-stage loading, encrypted command-and-control traffic, security-product enumeration, and process injection behavior.
The ecosystem appears to have evolved from activity attributed to a single cybercrime group into a broader malware family reused and redeveloped by multiple criminal operators and some APT-linked actors, aided in part by leaked source code such as Winos 4.0. Public reporting has also linked Silver Fox-adjacent tooling and infrastructure to Golden Eye Dog. Silver Fox has become notable for its modularity, mutable build variants, anti-detection adaptations, and sustained targeting of Windows users in the Chinese internet ecosystem through socially engineered software-installation lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently, the Knownsec 404 Advanced Threat Intelligence Team has frequently detected Silver Fox attack activities that mimic popular tools.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparative sample sharing a marker with AtlasRAT; no direct operational role in this report is established.
Referenced as part of a prior investigation and pivot chain tied to the same hosting infrastructure. The content does not provide functional malware details beyond indicating it is associated with earlier campaign mapping.
Referenced as a trojan involved in stealing activities in prior public reporting related to the broader actor/tooling context.
A modular Trojan family spread via fake software download pages, SEO poisoning, phishing sites, and fake Flash update lures. It compromises hosts through malicious installers and supports remote control and data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.