Silver Fox counterfeit-installer SEO-poisoning campaign across Asia
Campaign
Summary
Hide ▲
Show ▼
Silver Fox is running a counterfeit-installer SEO-poisoning campaign that delivers malware across Asia and puts technology, education, and state-owned enterprise users at renewed risk. The operation uses bogus installer downloads and repeated search poisoning to drive infections. It shows sustained distribution activity rather than a one-off lure.
Related Happenings
Silver Fox MODBEACON Rust RAT activity
Malware Activity
H score23
First: 10.07.2026 16:15
Last: 10.07.2026 16:15
Sources 1
How related:
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
About this happening:
The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...
Silver Fox MODBEACON Rust RAT activity
Malware ActivityHow related: The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
About this happening: The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
Campaign
H score36
First: 04.05.2026 14:57
Last: 04.05.2026 14:57
Sources 1
About this happening:
Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
CampaignAbout this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
InstallFix Claude Code malvertising campaign
Campaign
H score32
First: 06.03.2026 17:00
Last: 06.03.2026 17:00
Sources 1
About this happening:
InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...
InstallFix Claude Code malvertising campaign
CampaignAbout this happening: InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...
Silver Fox Microsoft Teams SEO poisoning campaign
Campaign
H score32
First: 04.12.2025 19:25
Last: 04.12.2025 19:25
Sources 1
About this happening:
The Silver Fox operation is using SEO poisoning and Microsoft Teams lures to deliver ValleyRAT to Chinese-speaking users in China, making the campaign an activ...
Silver Fox Microsoft Teams SEO poisoning campaign
CampaignAbout this happening: The Silver Fox operation is using SEO poisoning and Microsoft Teams lures to deliver ValleyRAT to Chinese-speaking users in China, making the campaign an activ...
Timeline
-
10.07.2026 16:15 2 articles · 13d ago
Silver Fox counterfeit-installer SEO-poisoning campaign across Asia
Initial DisclosureIn mid-June 2026, Silver Fox distributors used counterfeit software installers and SEO poisoning to push malicious ZIP payloads. The observed phase targeted technology, education, and state-owned enterprise users across Asia.
Show sources
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic — thehackernews.com — 10.07.2026 16:15
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic — thehackernews.com — 10.07.2026 16:15