Related Threat Clusters
-
Urgent CISA Directive: Patch Critical Ivanti EPMM Vulnerability CVE-2026-1340 by April 11
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. federal agencies patch a critical vulnerability in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1340, by April 11, 2026.…
23 articles · Updated April 8, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026 -
Silver Fox Cyber Campaign Exploits Fake Tax Alerts to Spread Malware
The Silver Fox threat group, linked to China, has initiated a new cyber campaign targeting businesses and individuals in Asia. This campaign employs deceptive tactics, including fake tax audit notifications and…
16 articles · Updated April 28, 2026 -
Silver Fox Targets Japanese Firms with Spearphishing During Tax Season
The Silver Fox cyber threat group is conducting a targeted spearphishing campaign against Japanese businesses, particularly manufacturers, during the annual tax filing and corporate restructuring season. The attackers…
8 articles · Updated March 26, 2026 -
Cyber Campaign Targets Cambodia with Spark RAT via BYOVD Technique
A new cyber campaign has emerged, targeting individuals and organizations in Cambodia with the Spark RAT, an open-source remote access trojan. The attackers utilize a sophisticated multi-stage infection chain, employing…
2 articles · Updated August 28, 2026 -
Silver Fox APT Campaign Distributes ValleyRAT via Fake Telegram Installer
A new malware campaign linked to the Silver Fox APT group has been identified, utilizing a fake Chinese language pack installer for Telegram to deliver ValleyRAT, a sophisticated remote access trojan. The malicious MSI…
2 articles · Updated April 9, 2026 -
ValleyRAT Backdoor Disguised as Signed Adware
The ValleyRAT backdoor has been discovered masquerading as a legitimate adware application, specifically a modified version of QN Wallpaper. This malware, attributed to the threat actor Silver Fox, utilizes DLL…
5 articles · Updated August 31, 2026 -
Silver Fox APT Deploys ValleyRAT via Fake Installers Targeting China
The Silver Fox APT group has launched a campaign targeting users in China by distributing malware through fake installers of popular applications, including Microsoft Teams. The malware, known as ValleyRAT, employs…
2 articles · Updated December 4, 2025 -
Silver Fox APT Targets Taiwan with Winos 4.0 Malware Campaign
Silver Fox APT is conducting targeted attacks in Taiwan utilizing DLL sideloading and BYOVD techniques to deploy Winos 4.0 (ValleyRat). The campaigns leverage localized phishing lures related to tax and e-invoice…
4 articles · Updated February 23, 2026 -
Chinese Hackers Use Fake Teams Downloads to Shift Blame to Russia
A Chinese state-linked hacking group, Silver Fox (Void Arachne), is conducting a campaign that mimics Microsoft Teams downloads to mislead users into believing Russian attackers are responsible. This operation targets…
3 articles · Updated December 18, 2025
Recent Intelligence Reports
- ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
- ValleyRAT masquerading as adware — Securelist · August 31, 2026
- New campaign targets Cambodia with Spark RAT using BYOVD technique | brief — Scworld · August 28, 2026
- 120038 — securelist.com · August 13, 2026
- Risky Bulletin: China arrests members of Silver Fox cybercrime group — News.Risky.Biz · June 17, 2026
- New Silver Fox Campaign Uses Fake Tax Audit Alerts and Software Updates to Deliver Malware — Cybersecuritynews · April 28, 2026
- Fake Tax Audits and Updates Fuel Silver Fox Malware Campaign — Gbhackers · April 28, 2026