Last seven days
- First activity
- Aug 31, 2026
- Last activity
- Sep 4, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 17 hostnames
SilverFox, also known as Yinhu, is a Windows-focused remote-access Trojan ecosystem used in campaigns primarily targeting Chinese-speaking users and organizations.
Profile source: Mallory opens in a new tabSilverFox
SilverFox, also known as Yinhu, is a Windows-focused remote-access Trojan ecosystem used in campaigns primarily targeting Chinese-speaking users and organizations. Operations have used spoofed software-download websites, SEO poisoning and watering-hole delivery, and instant-messaging spearphishing to distribute malware masquerading as legitimate software installers or business-themed documents. The activity has impersonated widely used productivity, remote-access, browser, security, and communications products.
SilverFox-related payloads employ DLL side-loading, staged in-memory payload execution, process injection and process hollowing, anti-debugging and virtual-machine evasion, code and configuration obfuscation, and security-tool impairment. Observed functions include host, process, file, and directory discovery; credential and email collection; keylogging; screen and clipboard capture; persistence through startup mechanisms, scheduled tasks, and services; and command-and-control-based data exfiltration. Some variants use RPC-based command-and-control communications and encrypted payloads or configuration data.
SilverFox activity has been associated with ValleyRAT, Winos 4.0, Gh0stRAT-derived tooling, HoldingHands, UTG-Q-1000, VoidArachne, and ValleyThief. Public reporting identifies overlap among these tools, but operator-level attribution remains unresolved.
C2 tracking
Derp observations, rolling seven-day window
Samples
4ba01b04681a5273facdd8b17e7b7b2246ee0eab6168c932946e7e96b9099e2d 765d34b234970be7eb12351051eff45d5d9cab515da07e4615381eacdc672d3b 86b34bd9245e406c15c88d0b5b8b11ae34f52bf1c16a1e0a0bfe80780efbda8c a2a4be3a4b8c9738d92ff0dfa13886e2a629f9f820e2169ed33c883dc548ce4b da169efdf43f4f2e87937efaaaf328dd659e28740411d1904a5bd0908ea5e061 52e889aa77ee3e84835f700f19ea091d48b7e0682c13cba6941129cdf9de27ba 0a3061ce09d7e3cb2b3d3453432da69ee83b59b782853d1f6462fd177db75a7a 367314385c4bc2f97e4a1d5b9a1612ec6f71ad0b51cf0754c19f7275f916e386 7813b7a31ac9f251e26156496d61c44b4b14aff5390b8212b050033975395d7c ec4ea2c3851c910fa98f99e2a3cf161022b4511a1c56e1fcc3a5d2e07542b279 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.