Skip to content
Malware family

SilverFox

SilverFox is a China-focused Windows malware family commonly described in the provided reporting as a remote access trojan (RAT), with additional overlap to infostealer and Winos/Gh0stRAT-derived tooling.

Profile source: Mallory opens in a new tab

SilverFox

Family profile

SilverFox is a China-focused Windows malware family commonly described in the provided reporting as a remote access trojan (RAT), with additional overlap to infostealer and Winos/Gh0stRAT-derived tooling. Public reporting cited here says it is actively used by cybercrime groups to target Chinese-speaking users, and that attack activity has intensified. Delivery has been observed through SEO-driven watering-hole and phishing sites masquerading as legitimate software download pages, trojanized software installers, office-software-themed packages, ZIP archives, and malicious LNK-based chains. Impersonated software and lures mentioned in the content include Feishu, ToDesk, Sunflower, Tencent Meeting, i4Tools, Chrome, Xiaohongshu, DeepL, AnyDesk, Snipaste, Facebook, Panasonic software, and Trend Micro Titanium, as well as Chinese-language disciplinary-investigation themed executables.

Capabilities described across the reporting include remote access functionality, staged payload retrieval, in-memory decryption and execution, shellcode loading, process injection and hollowing, DLL side-loading, persistence via Task Scheduler RPC and Windows services, Defender exclusion commands, Windows Update disablement, anti-analysis and anti-debugging checks, anti-VM checks, and security-tool awareness including references to 360 products. One analyzed chain reconstructed Alibaba OSS staging URLs at jun616[.]oss-cn-beijing[.]aliyuncs[.]com/tad and 26nn[.]oss-cn-hangzhou[.]aliyuncs[.]com/drops, downloaded carrier files named a.gif, b.gif, c.gif, d.gif, s.dat, s.jpg, drops.jpg, image.png, and thumbs.db, and ultimately decoded a stage exporting Edge from rundll32.dat that used HKCU\SOFTWARE\Sauron, copied itself to C:\Windows\svchost.exe, created a service named Sauron, and contained downloader templates hxxp://%s/upx.rar, hxxp://%s/%d.dll, and hxxp://%s/ip.txt. Another SilverFox variant used a custom virtual machine, ChaCha20/Salsa20-style encryption, encrypted resource blobs, and Microsoft RPC over ncacn_ip_tcp via NdrAsyncClientCall for C2, with the actual host and port remaining unrecovered in static analysis.

Infrastructure associated with SilverFox phishing and malware delivery in the provided content is extensive. Knownsec reported 2,639 phishing website records tied to 1,285 unique domains and 609 IPs, with heavy use of .top domains, centralized hosting, and Let’s Encrypt certificates. The originating phishing site discussed was fndykokouviqndzc[.]cn at 24[.]233[.]31[.]22, with JARM 27d27d27d00027d1dc27d27d27d27d6bb109f6a86ac53b95e602f9b6ac44ca and a related download URL at http://www[.]zsyglvocqxpubdzk[.]cn. Additional infrastructure and indicators mentioned include 156[.]251[.]25[.]112 hosting 292 phishing domains, the OSS hosts above, and a separate LNK campaign using 46.161.0.94 that ReversingLabs classified as Win32.Trojan.Sonbokli and that reporting said may be linked to SilverFox, though final payload confirmation was not available. Attribution in the supplied material is mixed: SilverFox is repeatedly described as Chinese-origin and China-focused, but some reporting explicitly leaves operator attribution unresolved and places parts of the activity more broadly in the SilverFox/Winos/Gh0stRAT ecosystem rather than tying it to a definitively identified actor.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 21, 2026
Last activity
Jul 21, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • HK1

Leading providers

  • Cloudie Limited1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

SilverFox in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.