Skip to content

SilverFox

SilverFox, also known as Yinhu, is a Windows-focused remote-access Trojan ecosystem used in campaigns primarily targeting Chinese-speaking users and organizations.

Profile source: Mallory opens in a new tab

SilverFox

Family profile

SilverFox, also known as Yinhu, is a Windows-focused remote-access Trojan ecosystem used in campaigns primarily targeting Chinese-speaking users and organizations. Operations have used spoofed software-download websites, SEO poisoning and watering-hole delivery, and instant-messaging spearphishing to distribute malware masquerading as legitimate software installers or business-themed documents. The activity has impersonated widely used productivity, remote-access, browser, security, and communications products.

SilverFox-related payloads employ DLL side-loading, staged in-memory payload execution, process injection and process hollowing, anti-debugging and virtual-machine evasion, code and configuration obfuscation, and security-tool impairment. Observed functions include host, process, file, and directory discovery; credential and email collection; keylogging; screen and clipboard capture; persistence through startup mechanisms, scheduled tasks, and services; and command-and-control-based data exfiltration. Some variants use RPC-based command-and-control communications and encrypted payloads or configuration data.

SilverFox activity has been associated with ValleyRAT, Winos 4.0, Gh0stRAT-derived tooling, HoldingHands, UTG-Q-1000, VoidArachne, and ValleyThief. Public reporting identifies overlap among these tools, but operator-level attribution remains unresolved.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Sep 4, 2026
Feed role
C2 / Distribution
Host form
4 IP / 17 hostnames

Leading locations

  • HK12
  • US5

Leading providers

  • POWER LINE DATACENTER6
  • FASTNET DATA INC2
  • Alibaba (US) Technology Co., Ltd.1
  • Cloudflare, Inc.1
  • Cloudie Limited1
  • cognetcloud INC1

Infrastructure traits

  • Hosting 16
  • Anycast 1

Samples

Recent associated samples

MITRE ATT&CK

SilverFox in ATT&CK

41 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.