dti.domaintools.com 8/21/2026, 5:06:43 PM · external

Silver Fox malware network adapts, uses cloud to launch attacks

CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

THE article discusses ongoing activities of the Silver Fox malware delivery network, known for targeting Chinese-speaking users with typo-squatted domains and malware designed to imitate trusted software. Even after the arrest of several operators in June 2026, the network remains active and adapts quickly. Recent trends show an increase in malicious domains and exploitation of cloud services (AWS, Google Cloud, Alibaba) for payload delivery.

The malware typically uses modified versions of Gh0stRAT, combined with advanced techniques like file padding to evade detection. The article also categorizes operators into clusters based on their distinct targets and infrastructure models. A robust command and control (C2) mechanism is employed, utilizing tools for traffic redirection and analytics. Lastly, it lists indicators of compromise (IoCs) for further investigation and mitigation.

View full article

Article by CyberSIXT