Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit

Sainbox RAT and the open-source Hidden rootkit have been delivered by a new campaign that uses phony websites that promote well-known programs like WPS Office, Sogou, and DeepSeek.

Due on tradecraft parallels with earlier efforts attributed to the threat actor, the activity has been traced with medium confidence to a Chinese hacker collective known as Silver Fox (also known as Void Arachne).

The distribution of malicious MSI installers in Chinese by the phishing websites (“wpsice[.]com”) suggests that the campaign’s target audience is Chinese speakers. According to researcher Leandro Fróes of Netskope Threat Labs, the malware payloads consist of the Sainbox RAT, a variation of the Gh0st RAT, and a version of the open-source Hidden rootkit.

This approach is not the first time the threat actor has used it. eSentire described an operation in July 2024 that used phony Google Chrome websites read more more about Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *