Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit
Sainbox RAT and the open-source Hidden rootkit have been delivered by a new campaign that uses phony websites that promote well-known programs like WPS Office, Sogou, and DeepSeek.
Due on tradecraft parallels with earlier efforts attributed to the threat actor, the activity has been traced with medium confidence to a Chinese hacker collective known as Silver Fox (also known as Void Arachne).
The distribution of malicious MSI installers in Chinese by the phishing websites ("wpsice[.]com") suggests that the campaign's target audience is Chinese speakers. According to researcher Leandro Fróes of Netskope Threat Labs, the malware payloads consist of the Sainbox RAT, a variation of the Gh0st RAT, and a version of the open-source Hidden rootkit.
This approach is not the first time the ...

