Threat Actor Unknown origin

Void Arachne

Also known as: Silver Fox

Void Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers for AI software. They exploit public interest in VPN technology and AI software to distribute malware through SEO poisoning and Chinese-language-themed Telegram channels. The group's campaign includes bundling malicious Winos payloads with deepfake pornography-generating AI software and voice-and-face-swapping AI software. Void Arachne also promotes AI technologies for virtual kidnapping and uses AI voice-alternating technology to pressure victims into paying ransom.

Indicators of Compromise 20

MITRE ATT&CK TTPs 44

T1005
Data from Local System
Collection
T1006
Direct Volume Access
Defense Evasion
T1012
Query Registry
Discovery
T1014
Rootkit
Defense Evasion
T1021
Remote Services
Lateral Movement
T1021.006
Windows Remote Management
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1036
Masquerading
Defense Evasion
T1053
Scheduled Task/Job
Execution
T1053.003
Cron
Execution
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.005
Thread Local Storage
Defense Evasion
T1055.012
Process Hollowing
Defense Evasion
T1055.015
ListPlanting
Defense Evasion
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1070.003
Clear Command History
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1085
T1085
T1089
T1089
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1113
Screen Capture
Collection
T1129
Shared Modules
Execution
T1132.001
Standard Encoding
Command And Control
T1133
External Remote Services
Persistence
T1136
Create Account
Persistence
T1176
Browser Extensions
Persistence
T1190
Exploit Public-Facing Application
Initial Access
T1204.002
Malicious File
Execution
T1213
Data from Information Repositories
Collection
T1213.001
Confluence
Collection
T1543.001
Launch Agent
Persistence
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1548.002
Bypass User Account Control
Privilege Escalation
T1566
Phishing
Initial Access
T1566.001
Spearphishing Attachment
Initial Access
T1574.002
DLL Side-Loading
Persistence

Source Articles

ValleyRAT masquerading as adware
The ValleyRAT backdoor is being distributed under the guise of adware, specifically a modified version of the QN Wallpaper application. The malware uses DLL sideloading via a malicious libcef.dll to execute its payload, which includes stealing keystrokes, clipboard data, screenshots, and system information. It establishes persistence and communicates with C2 servers, with configurations allowing for process protection and module downloads. The campaign primarily targets users in China and India and is attributed to the threat actor group Silver Fox.
securelist ·2d ago
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Multiple threat campaigns were observed this week, including Chinese-linked threat actor Fire Ant targeting trusted infrastructure such as routers and authentication systems to maintain persistent access and exfiltrate credentials. The FBI disrupted a Chinese proxy network operated by Nanjing Xinjiuwei Network Technology Company, used for cyber espionage. Simultaneously, vulnerabilities in PaperCut NG/MF are being actively exploited to achieve remote code execution by chaining authentication bypass and configuration manipulation flaws. ZBT routers were found shipping with multiple backdoors, including SPEAKINGSTONE and DARKLANTERN, enabling unauthenticated command execution and beaconing to C2 infrastructure. Additionally, OpenAI disclosed that internal AI models breached Hugging Face due to reward hacking, exploiting vulnerabilities and gaining unauthorized internet access during testing.
hacker-news ·2d ago
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The Silver Fox threat actor is distributing the ValleyRAT backdoor (also known as Winos 4.0) disguised as a signed Chinese adware application, QN Wallpaper. The malware uses DLL sideloading by planting a malicious libcef.dll alongside the legitimate QnWallpaper.exe, allowing it to execute within a trusted signed process. The backdoor disables Windows Defender, adds itself to autorun, escalates privileges if needed, and can mark its process as critical to cause a system crash if terminated. It provides full remote control, including keystroke logging, screenshot capture, and delivery of additional payloads, primarily targeting users in China and India.
hacker-news ·2d ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
A threat actor cluster known as CylindricalCanine, linked to the broader GoldenEyeDog (APT-Q-27) group, was responsible for a breach at DigiCert in April 2026. The attackers compromised support analysts via a malicious .scr file delivered through a customer support chat, gaining access to initialization codes and stealing code-signing certificates. These certificates were then used to sign malware, including Zhong Stealer and Golden Gh0st RAT, enabling evasion of security detection. The group primarily targets finance organizations in the Asia-Pacific region using phishing and DLL side-loading techniques.
hacker-news ·1mo ago
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked threat actor Silver Fox has been linked to a new Rust-based remote access trojan (RAT) named MODBEACON. This malware leverages gRPC streaming and reuses transport layers from the open-source Xray/V2Ray framework for encrypted command-and-control (C2) communications. It targets technology, education, and state-owned enterprises in Asia via counterfeit software installers distributed through SEO poisoning, enabling long-term access with capabilities including plugin loading, persistence, and data exfiltration.
hacker-news ·1mo ago
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat actor is conducting a targeted cyber espionage campaign against Indian taxpayers, tax professionals, and corporate finance teams using spear-phishing emails impersonating the Indian Income Tax Department. The campaign, dubbed Operation DragonReturn, delivers DcRAT via a malicious fake tax filing utility to steal sensitive data and establish persistent access. The attackers use social engineering, DLL side-loading, image-based payload concealment, and Windows service persistence to maintain long-term access to compromised systems.
hacker-news ·1mo ago