Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2
- Host form
- 11 IP / 2 hostnames
SilverFox is a China-focused Windows malware family commonly described in the provided reporting as a remote access trojan (RAT), with additional overlap to infostealer and Winos/Gh0stRAT-derived tooling.
Profile source: Mallory opens in a new tabSilverFox
SilverFox is a China-focused Windows malware family commonly described in the provided reporting as a remote access trojan (RAT), with additional overlap to infostealer and Winos/Gh0stRAT-derived tooling. Public reporting cited here says it is actively used by cybercrime groups to target Chinese-speaking users, and that attack activity has intensified. Delivery has been observed through SEO-driven watering-hole and phishing sites masquerading as legitimate software download pages, trojanized software installers, office-software-themed packages, ZIP archives, and malicious LNK-based chains. Impersonated software and lures mentioned in the content include Feishu, ToDesk, Sunflower, Tencent Meeting, i4Tools, Chrome, Xiaohongshu, DeepL, AnyDesk, Snipaste, Facebook, Panasonic software, and Trend Micro Titanium, as well as Chinese-language disciplinary-investigation themed executables.
Capabilities described across the reporting include remote access functionality, staged payload retrieval, in-memory decryption and execution, shellcode loading, process injection and hollowing, DLL side-loading, persistence via Task Scheduler RPC and Windows services, Defender exclusion commands, Windows Update disablement, anti-analysis and anti-debugging checks, anti-VM checks, and security-tool awareness including references to 360 products. One analyzed chain reconstructed Alibaba OSS staging URLs at jun616[.]oss-cn-beijing[.]aliyuncs[.]com/tad and 26nn[.]oss-cn-hangzhou[.]aliyuncs[.]com/drops, downloaded carrier files named a.gif, b.gif, c.gif, d.gif, s.dat, s.jpg, drops.jpg, image.png, and thumbs.db, and ultimately decoded a stage exporting Edge from rundll32.dat that used HKCU\SOFTWARE\Sauron, copied itself to C:\Windows\svchost.exe, created a service named Sauron, and contained downloader templates hxxp://%s/upx.rar, hxxp://%s/%d.dll, and hxxp://%s/ip.txt. Another SilverFox variant used a custom virtual machine, ChaCha20/Salsa20-style encryption, encrypted resource blobs, and Microsoft RPC over ncacn_ip_tcp via NdrAsyncClientCall for C2, with the actual host and port remaining unrecovered in static analysis.
Infrastructure associated with SilverFox phishing and malware delivery in the provided content is extensive. Knownsec reported 2,639 phishing website records tied to 1,285 unique domains and 609 IPs, with heavy use of .top domains, centralized hosting, and Letβs Encrypt certificates. The originating phishing site discussed was fndykokouviqndzc[.]cn at 24[.]233[.]31[.]22, with JARM 27d27d27d00027d1dc27d27d27d27d6bb109f6a86ac53b95e602f9b6ac44ca and a related download URL at http://www[.]zsyglvocqxpubdzk[.]cn. Additional infrastructure and indicators mentioned include 156[.]251[.]25[.]112 hosting 292 phishing domains, the OSS hosts above, and a separate LNK campaign using 46.161.0.94 that ReversingLabs classified as Win32.Trojan.Sonbokli and that reporting said may be linked to SilverFox, though final payload confirmation was not available. Attribution in the supplied material is mixed: SilverFox is repeatedly described as Chinese-origin and China-focused, but some reporting explicitly leaves operator attribution unresolved and places parts of the activity more broadly in the SilverFox/Winos/Gh0stRAT ecosystem rather than tying it to a definitively identified actor.
C2 tracking
Derp observations, rolling seven-day window
Samples
0e8a7e1488d7e2ab614d36c7be3decfc66f3a8c0d1d997d6fc4bd23dbc3e9db4 3dcb2d87765159534b187b9a2fe8fff6412b184304aa8c154ab093a934e02a11 68d92f3e92a41614297a82eec91dbf693664798e221eb9ec60a248b7682efed3 690b3aacb438e50788ca6018d18caa7bd1d18121e71649e7d2e36067919ca0d6 a42df8053e42a3f98ce47aa8a0d130c0aa939d3dd9a8585011ddd665a8463fe0 7ea6eb25a6dd947a8cd28328903596cef8b6894f909a282dac596e8dd25903ba 960ae7aabae262723177420c318c5e1d834f081ba917f044cc52c9bf39fa4e2a 04bc0dbf904d347bfa0b064bb436650fad0583b550dbd9450c8d00f4cb5a3b1b 0a3061ce09d7e3cb2b3d3453432da69ee83b59b782853d1f6462fd177db75a7a 12b920865bc8bd9bad20650a0f7849fe2856de3d72bc5f1a93bb288e8eefaca2 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.