Silver Fox is a China-linked threat actor associated with both cybercrime and state-aligned intrusion activity. It is widely tracked under the name Silver Fox and has also been referred to as Void Arachne; additional reporting has linked the group to aliases such as SwimSnake and The Great Thief of Valley, though alias mapping is not uniformly accepted across vendors. Reporting consistently associates Silver Fox with Chinese-language tooling, infrastructure patterns, and victimology, and several researchers characterize it as a Chinese cybercrime group while others describe it as state-associated or China-aligned. The group appears to operate at the boundary between financially motivated intrusion activity and espionage-oriented collection. Silver Fox has been active since at least 2022 and became especially prominent through campaigns involving ValleyRAT, also known as Winos 4.0 or WinOS, a malware family strongly associated with the actor. Its broader malware ecosystem has been reported to include Gh0st RAT variants, MODBEACON, ABCDoor, Atlas RAT, RomulusLoader, SilentRunLoader, and related loaders, stealers, and support components. Some reporting suggests the ecosystem has expanded through leaked or redeveloped code, enabling reuse by multiple clusters and complicating attribution when ValleyRAT-derived tooling appears outside clearly attributable Silver Fox operations. The actor targets organizations across Asia and beyond, including victims in Japan, China, India, Indonesia, Russia, Taiwan, and other countries. Observed sectors include industrial manufacturing, healthcare, public sector, technology, education, state-owned enterprises, consulting, trade, transport, finance-related functions, and tax or accounting ecosystems. Silver Fox frequently tailors lures to local language and business context, with recurring themes involving tax notices, invoices, salary or HR notifications, software downloads, and counterfeit productivity or utility applications. Initial access most commonly relies on phishing, spear-phishing, malicious archives, fake software installers, SEO poisoning, typosquatted websites, and abuse of messaging or file-sharing platforms. Delivery chains often use DLL sideloading with legitimate signed executables, trojanized installers, and multi-stage loaders. Silver Fox has repeatedly hidden payloads in image or non-executable carrier files, including steganographic or trailer-based encoding schemes, and has used fileless or memory-resident execution to reduce forensic visibility. Silver Fox demonstrates strong emphasis on defense evasion and persistence. Reported techniques include dynamic API resolution, anti-analysis checks, user-mode hook removal through NTDLL restoration, AMSI bypass, process injection, thread-context hijacking, scheduled-task persistence, Windows service persistence, watchdog processes or scripts, and layered recovery mechanisms to relaunch implants if terminated. The actor is also notable for repeated use of bring-your-own-vulnerable-driver techniques and malicious or abused signed drivers to disable or tamper with endpoint security products. Public reporting has linked Silver Fox activity to drivers used for kernel-mode process termination, rootkit-style IOCTL functionality, and support or watchdog roles. ValleyRAT-centric intrusions attributed to Silver Fox have been described as unusually complex, including long multi-stage chains, shellcode loaders, in-memory execution, modular plugin support, and in some cases kernel-level rootkit functionality. Associated malware has been reported to support remote command execution, host profiling, file transfer, screenshot capture, keylogging, clipboard theft, credential and data theft, SOCKS-style proxying, plugin loading, and delivery of additional payloads. Some campaigns also deployed malware aimed at persistent remote access and near-real-time monitoring of victim systems. Silver Fox has shown a recurring interest in tax-themed social engineering. Multiple campaigns have impersonated tax authorities in India, Russia, and Indonesia to target taxpayers, tax professionals, finance teams, and enterprises during filing periods or regulatory transitions. Other campaigns have used invoice lures, HR notifications, and fake software updates or downloads. The actor has also been observed abusing legitimate cloud and content-delivery services as staging or command-and-control infrastructure. Attribution around some adjacent clusters remains unsettled. TA4922 has been reported to share overlaps with Silver Fox in tooling, infrastructure, and social engineering, but the exact relationship is not fully resolved. Likewise, some campaigns involving ValleyRAT or related malware have only been linked to Silver Fox with low to moderate confidence because the malware ecosystem appears to be reused by multiple actors. Even so, Silver Fox remains the threat actor most consistently and prominently associated with ValleyRAT/Winos 4.0 operations. Overall, Silver Fox is best understood as a prolific China-linked intrusion actor or ecosystem centered on modular remote access malware, phishing-led delivery, DLL sideloading, aggressive defense evasion, and frequent use of vulnerable-driver abuse. Its operations span opportunistic cybercrime, credential and data theft, and activity consistent with strategic collection against organizations of governmental, industrial, and economic interest.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
28 malware families attributed to this actor across reporting.
23 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NsecSoft NSecKrnl driver, identified as CVE-2025-68947, is a signed kernel-mode driver that exposes functionality for arbitrary process termination. By exploiting this capability, the ransomware is able to terminate the processes of major EDR and antivirus products...
CVE-2023-52271 documents how an affected version of wsftprm.sys can be abused to terminate protected processes.
617 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Prolific threat group noted only as overlapping to some extent with TA4922 in the discussed campaign.
Conducting a phishing-led intrusion targeting a Japanese industrial manufacturing organization, using DLL sideloading, BYOVD, NTDLL unhooking, process injection, registry-based payload storage, scheduled-task persistence, and dual recovery mechanisms to deploy ValleyRAT for remote access.
Mentioned only as another Chinese cybercrime group that uses Gh0st RAT.
Conducting spear-phishing campaigns against Russian organizations using tax-themed lures to deliver a customized Rust loader, ValleyRAT, and the previously undocumented Python backdoor ABCDoor. The group is described as pursuing both cyber-espionage and financially motivated operations, including theft, fraud, and cryptominer deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.