The Chinese cybercrime group Silver Fox is using typosquatted domains that mimic trusted software brands, including Surfshark VPN, Signal, Telegram, Zoom, and Autodesk, to trick Chinese-speaking users into downloading ZIP archives containing trojanized installers. Researchers said the installers deploy a malicious Autodesk binary that loads shellcode, retrieves command-and-control details, and pulls the newly documented AtlasCross RAT into memory from bifa668[.]com over TCP port 9899, marking a shift from the group’s earlier Gh0st RAT-based tools such as ValleyRAT and Winos 4.0.
AtlasCross RAT includes defense-evasion and post-compromise features such as AMSI and ETW bypasses, ChaCha20-encrypted C2 traffic, embedded PowerChell execution, DLL injection, RDP session hijacking, WeChat DLL injection, and disruption of Chinese security products. Reporting from multiple security firms indicates Silver Fox is conducting both broad cybercrime activity and more targeted intrusions across Asia, with victims and targeting tied to Taiwan, India, Japan, and Southeast Asia, while reuse of a stolen code-signing certificate suggests an effort to make payloads appear legitimate and improve evasion for data theft and financial fraud operations.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Breakglass Intelligence reported that a suspected Silver Fox / APT-Q-27 infrastructure cluster, including jackadmin and jackbank panel domains, was registered using the name 罗泉 (Luo Quan) and the email ylfwq002@gmail.com, describing it as an operational security failure. The analysis also linked the cluster to Alibaba Cloud Hong Kong hosting and a large SEO-poisoning lure network, while assessing only medium confidence that Luo Quan is the operator's real-world identity.
A weaponized MSI masquerading as a Telegram Chinese language pack was reported on MalwareBazaar on 2026-04-08, delivering ValleyRAT through a multi-stage chain that used ZPAQ archives, a legitimate ByteDance binary for conditional DLL sideloading, and a kernel-mode rootkit/BYOVD technique. Researchers linked the tooling, infrastructure, lure theme, and AV-evasion logic to Silver Fox despite the campaign using the older ValleyRAT family rather than AtlasCross RAT.
Additional reporting from Knownsec 404, eSentire, Sekoia, and ESET said Silver Fox was conducting both broad cybercrime campaigns and more targeted operations affecting organizations in Taiwan, India, Japan, and several Southeast Asian countries. The campaign also showed operational maturity through reuse of a stolen code-signing certificate across multiple malware efforts.
Hexastrike and other cited researchers described the malware's infection chain, including shellcode loading, retrieval of C2 information, and in-memory download from bifa668[.]com over TCP port 9899. They also documented features such as PowerChell-based AMSI and ETW bypasses, ChaCha20-encrypted C2 traffic, WeChat DLL injection, RDP session hijacking, and disruption of Chinese security products.
An active campaign targeted Chinese-speaking users with fake download sites impersonating brands including Surfshark VPN, Signal, Telegram, Zoom, and Autodesk-related software delivery themes. Victims were lured into downloading ZIP installers containing trojanized binaries that ultimately loaded AtlasCross RAT in memory.
Reporting indicates the Silver Fox cybercrime group evolved from prior Gh0st RAT-based malware such as ValleyRAT and Winos 4.0 to a newly documented malware family called AtlasCross RAT, reflecting a more mature toolset for theft and fraud operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 64 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.