SilentRunLoader is a Python-based loader and information stealer associated with the Chinese-speaking, financially motivated threat cluster TA4922, with reported tooling overlap to the broader Silver Fox ecosystem. It has been used in campaigns targeting organizations in the United Kingdom and Southeast Asia, particularly through localized tax, benefits, compliance, and other business-themed social-engineering lures. Delivery has been observed via phishing-linked archives and DLL sideloading.
The malware combines staging and theft functions. It is used to deploy additional tooling while also harvesting data from Google Chrome, including stored credentials, session cookies, and browsing history or related browsing information. Reported behavior includes collecting browser data, archiving the stolen material, and exfiltrating it to attacker-controlled infrastructure. In some observed intrusions, SilentRunLoader also downloaded or dropped an additional executable as a next-stage component to continue data theft activity.
SilentRunLoader has been described as a compiled Python utility and as both a loader and a Chrome-focused stealer, making it notable within TA4922’s toolkit for blending payload delivery with immediate browser-data theft. Researchers have also noted code artifacts consistent with rapid or minimally reviewed development, and assessed with high confidence that large language models likely assisted development of some of TA4922’s newer Python malware, including SilentRunLoader. Its use reflects TA4922’s broader pattern of high-volume, regionally tailored phishing operations aimed at credential theft, fraud, data theft, and establishing access inside victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This new development indicates Silver Fox is actively refining its tradecraft, expanding its arsenal with malware families like Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader.
Another alarming component of the group’s toolkit is a compiled Python utility called SilentRunLoader. This stealthy program is designed to gather sensitive browser data from local machines.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent months, however, attacks mounted by the hacking group have relied on phishing campaigns using human resources- and business-themed lures for credential phishing, fraud, and malware delivery, including Atlas RAT, RomulusLoader, and SilentRunLoader.
Atlas RAT ... connected to a command-and-control server at 206.238.115.58 over port 886... Network defenders should flag traffic to unusual ports, particularly port 1234, used by RomulusLoader’s C2 infrastructure.
These campaigns delivered credential phishing, fraud, and a newly identified malware called Atlas RAT. New loader families, designated RomulusLoader and SilentRunLoader, were also introduced to stage additional tools. | New loader families, designated RomulusLoader and SilentRunLoader, were also introduced to stage additional tools.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader malware family listed as part of Silver Fox's expanding arsenal.
A compiled Python malware utility that steals browser data from Google Chrome, including saved credentials, session cookies, and browsing history, archives the data, and uploads it to a remote server. The report suggests it may have been rapidly developed with LLM assistance.
A loader family introduced in TA4922 campaigns to stage additional tools.
SilentRunLoader is a Python-based malware/loader used in phishing campaigns that steals Chrome credentials and exfiltrates them to attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.