Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors silverfox

Also known as: Void Arachne, SwimSnake, tracked as, YouSnake, UTG-Q-1000, TA4922, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

Silverfox is a highly adaptive threat actor that operates under a multitude of aliases—including Void Arachne, SwimSnake, Sandworm Team, Shell Crew, and Deep Panda—making attribution challenging. The group’s primary motive is cyber espionage, targeting a diverse array of sectors such as defense, finance, healthcare, energy, and media across more than thirty countries including China, the United States, Russia, India, and Israel. Operationally, Silverfox leverages two main delivery vectors identified by LevelBlue. First, counterfeit installers are distributed to Chinese‑speaking users; these packages employ advanced techniques such as Pool Party Variant 7 process injection and build‑time code obfuscation (junk code insertion, memory size checks). Second, malicious email campaigns deliver ZIP archives populated with executable payloads—often combining EXE files and DLLs that hijack legitimate Windows binaries via DLL sideloading. These attachments trigger fileless execution by injecting Donut‑generated shellcode, thereby bypassing traditional AV detection. The actor establishes persistence predominantly through registry modifications (e.g., adding startup entries) while also enabling remote access capabilities for command and control operations. In addition to theft of credentials through email collection and password‑store exploitation, Silverfox has been observed performing data staging, encryption, and exfiltration via both standard application‑layer protocols and alternative channels. Recent detections indicate a marked increase in volume from 2025 into 2026, suggesting an intensifying campaign. Strategic patterns reveal that Silverfox conducts opportunistic phishing tied to cultural themes—such as tax‑related lures targeting India and Russia—and occasionally exploits software supply chains by hijacking ostensibly trusted applications. While the group is heavily involved in espionage, sporadic exploitation of public‑facing assets points to a dual focus on intelligence gathering and tactical disruption. In sum, Silverfox exemplifies an adaptive, multi‑vector threat actor that blends fileless execution techniques with classic RAT functionality to infiltrate high‑value targets worldwide.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Manufacturing
Education
Non profit
Energy
Media
Critical infrastructure
Pharmaceutical
Think tank
Aviation
Hospitality
Aerospace
Retail
Information technology
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Utilities
Entertainment
Oil gas
Maritime
Construction

Targeted Countries / Regions

CN
US
RU
TW
IN
GB
IR
VN
JP
IL
AU
SA
PK
AE
UA
SG
KR
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 22 hours ago

Executive Summary

Silverfox—also known as Void Arachne, SwimSnake, and several other monikers—is an advanced espionage actor with a broad targeting scope spanning government, critical infrastructure, and commercial sectors across the globe. Using sophisticated delivery methods such as fake installers and spearphishing attachments containing DLL sideloading packs, Silverfox deploys ValleyRAT and related RAT families to achieve persistence, remote access, and data exfiltration. Recent activity shows an increase in detection volume and a focus on Chinese‑speaking users, indicating evolving operational tactics.

Goals & Targeting

Silverfox’s strategic objectives revolve around harvesting privileged data from entities deemed politically or economically valuable. By targeting sectors that house sensitive personal and national security information—such as defense contractors, telecom operators, healthcare facilities, and financial institutions—the actor seeks to gain access to proprietary technologies, diplomatic documents, or insider knowledge that can be leveraged for geopolitical advantage or future bargaining. The wide geographic reach of victims reflects an opportunistic approach: any organization with a perceived high value is fair game if it can be compromised via spearphishing or software supply‑chain attacks. Typical victims are midsize to large enterprises and public‑sector agencies spanning the US, EU, Asia, and Middle East. The actor prefers users who may have insufficient security awareness of sophisticated phishing attachments and benefits from leveraging industry‑specific supply chains such as medical device vendors or logistics software providers.

Enhanced Description

Key Capabilities

  • Advanced fileless delivery using Donut shellcode
  • DLL sideloading via rundll32 and process injection (Pool Party Variant 7)
  • Registry persistence mechanisms
  • Remote access trojan functionalities (ValleyRAT, ABCDoor, AtlasCross)
  • Credential harvesting and account manipulation
  • Spearphishing attachments with ZIP archives and custom installers
  • C2 over multiple application‑layer protocols
  • Evasion by junk code, memory checks, and sleeping timers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1190
T1566.001
T1114
T1071
T1087
T1078
T1110
T1068
T1547.001
T1059.004
T1583
T1584

Software / Tooling

ValleyRAT
ABCDoor backdoor
AtlasCross RAT
Cobalt Strike
Donut shellcode generator
Custom backdoors
rundll32.exe DLL sideloading
PowerShell scripts

Campaigns & Victims

Silverfox maintains a high operational tempo with overlapping campaigns that blend traditional spearphishing and software hijacking. Recent operations, such as the 2025–2026 ValleyRAT pushes, show increasing deployment density in Chinese‑speaking markets, while separate tax‑themed phishing waves target India and Russia. Victims are typically mid‑to‑large organizations with limited exposure to advanced threat hunting. The actor also demonstrates a capacity to scale attacks across multiple countries by reusing infrastructure—evidenced by the recurring 'TEMP' subdomains and shared malicious email patterns. Notable campaigns include the deployment of fake installers that exploited process injection, the use of ZIP attachments for DLL sideloading in Japan‑speaking contexts, and broader supply‑chain compromises where trusted medical software was leveraged to deliver RATs. While attribution remains fragmented across numerous aliases, operational analysis consistently points to a Russian or Iranian‑affiliated enterprise capable of exploiting both cloud and on‑prem environments.

IOC Patterns

  • Fake installer delivery targeting Chinese‑speaking users
  • ZIP attachments with EXE/DLL payloads for DLL sideloading
  • DLL side-loading via rundll32.exe
  • Process injection (Pool Party Variant 7)
  • Fileless execution using Donut‑generated shellcode
  • Registry modification for persistence
  • Remote access capabilities via custom RATs
  • Temporary domain aliases such as TEMP.* used for command & control

Recommended Actions

  • Block known malicious domains and IP addresses associated with Silverfox infrastructure.
  • Apply email filtering rules to quarantine spearphishing attachments, especially ZIP files containing EXE or DLL executables.
  • Deploy endpoint detection that flags DLL sideloading, process injection, and junk code patterns.
  • Audit and monitor registry keys for unauthorized startup entries or persistence mechanisms.
  • Restrict remote desktop and VPN access, requiring multi‑factor authentication and device whitelisting.
  • Maintain up‑to‑date antivirus signatures and enable sandbox analysis for suspicious attachments.
  • Educate users on spearphishing tactics and safe attachment handling practices.

Suggested Tags

APT
Espionage
RAT
Fileless
DLL Sideloading
Phishing
Supply-Chain Attack
China-US-Russia
Healthcare Software Hijacking

Confidence Assessment

The analysis is derived primarily from publicly available threat reports and limited source URLs, with substantial gaps in precise campaign timelines and verified attribution. Alias mapping (e.g., Silverfox vs. Deep Panda) introduces uncertainty regarding the entity’s exact composition. While technical details about ValleyRAT and delivery methods are corroborated by LevelBlue and ThreatBook sources, the broader strategic intent remains inferred from sector targeting patterns rather than direct evidence. Confidence is moderate for observed TTPs but low concerning actor attribution and operational scope.

ATT&CK Techniques

Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 6 IPv4 Address 3 URL 6 Domain 5

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: T1548
  3. www.fortinet.com — Cited by web research for: wsftprm.sys
  4. https://malpedia.caad.fkie.fraunhofer.de/actor/void_arachne — Cited by AI analysis.

Intel Summary

42

Techniques

50

Tools

0

Campaigns

54

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Backdoor / C2
APT
东亚 (East Asia)
malware
Espionage
RAT
Fileless
DLL Sideloading
Supply-Chain Attack
China-US-Russia
Healthcare Software Hijacking

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
55%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.