Victim Q&A · First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Short answer
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
Key points
- Silver Fox is a remote access trojan, not ransomware: it encrypts nothing and hides so it can use your PC and accounts for transfer fraud. Files that still open prove nothing.
- If money has moved, the police and the bank come before any technical step - the stop-payment window is measured in minutes.
- Disconnect but keep the power on: the payload, call-back addresses and session credentials in memory are what shows what the attacker did and what evidences the case.
- Change passwords, sign out sessions and freeze accounts from a separate clean device, and move every payment to call-back verification by phone or in person.
- Get removal tools only from vendor sites, and never read a clean scan as proof: recent variants delete security drivers from the kernel. Rebuild confirmed machines.
- Silver Fox has also been used to deliver ransomware, so check the servers, shares and backups the infected PC could reach.
In this order
What to do now
Money already sent: police first, then the bank
Call the police immediately - 110 in mainland China - describe it as an impersonation transfer fraud, and file with the local police station as soon as you can. The Ministry of Public Security's guidance on reporting telecom and online fraud asks victims to record the recipient's account number and name exactly and give them to officers, who then initiate an emergency stop-payment. Only a police instruction reaches the recipient account and the accounts downstream of it. 96110, China's national anti-fraud warning line, also takes fraud enquiries and reports, but once money has left, 110 is the direct route.
At the same time, call your relationship manager or the bank's corporate line to report the fraud and support the stop-payment, pull the online-banking USB key out of the infected PC, and hold every payment batch not yet executed. Have ready: time and amount, the recipient's account, name and bank, screenshots of the impersonation, and which computer and which person sent the payment. Outside mainland China the logic is identical: call local police and your bank's fraud team straight away.
Disconnect, but keep it powered on
Unplug the network cable and turn off Wi-Fi and any phone hotspot so the machine has no outside connection. Do not shut down, reboot or hibernate it, and do not run a one-click antivirus clean-up first. Silver Fox runs largely in memory; cutting power erases the payload, the call-back addresses and the credentials of live sessions, after which nobody can say what the attacker did and there is no technical evidence for the police or the bank. China's National Computer Virus Emergency Response Center gives the same advice: once a messaging or mail account is being misused, stop using the possibly infected computer and take it off the network. Do not delete the lure file, the chat history or the payment records.
Take the accounts back from a clean device
Work from a different computer or phone that you know is clean, never the infected one: the operator may still be connected, and keylogging would hand over the new password as well. For WeChat, QQ, WeCom, DingTalk and Lark, sign out of every device, change the password, turn on login protection and remove unfamiliar devices from the login device list on your phone. If you can no longer be sure the account is yours, WeChat lets you freeze it yourself through Security Center on the login screen, and Tencent customer service handles emergency freezes when self-service fails.
Change passwords and re-bind second factors for online banking, brokerage, payment and mail accounts. Until the computer is confirmed clean, an SMS code is not sufficient proof on its own.
Tell finance: every payment gets a call-back
Make sure finance, the cashier and everyone with payment authority knows right now that this computer and this account may be under someone else's control. Hold every pending payment, payee-account change and urgent payment, and verify each one by calling a number you already had - never a number supplied in the chat, and never a confirmation given only inside a messaging app. Operators routinely delete the real executive from the contact list, add an account with the same avatar and display name, and then open a "working group", so "it looks exactly like the boss" proves nothing.
Warn contacts and groups
By phone or from another account you trust, tell colleagues, customers, suppliers and every working group you belong to: files, links, QR codes and payment requests sent from this account since a given time must not be opened, forwarded or acted on. Ask group owners to take the suspicious files down, and ask anyone who already opened one to disconnect and report it too. Silver Fox reuses a compromised account to keep seeding groups, so one infection can spread across a whole contact list.
Preserve evidence, then sweep and rebuild
Where money has been lost, a finance or IT machine is involved, several PCs are affected or security software has been switched off, capture memory and disk first, extract the sample, call-back addresses and persistence method, sweep the whole estate for those indicators, and only then rebuild the confirmed machines. We take calls 24/7; incident response and forensics start remotely and come on site when needed, and the forensic report can be submitted as technical material with a police report.
Avoid making it worse
Do not
- Do not run a one-click antivirus clean-up and then reboot. It wipes the payload, call-back addresses and session credentials from memory, and with them any way to establish what the attacker did or where money and data went. Evidence first, removal second.
- Do not change passwords, sign into banking or reply to "the boss" on the infected machine. The operator may still be watching the screen and logging keystrokes, and the new password goes with them.
- Do not run a "Silver Fox removal tool" taken from a group chat, a search result or a download site. 360 has documented Silver Fox disguised as a security tool, even distributed under the file name "Prevent Silver Fox Trojan". Get tools only from the vendor's own site.
- Do not read "the removal tool found nothing" as "the machine is clean". Published analysis shows recent variants deleting security drivers from the kernel, hiding their own files and registry keys, and installing legitimate management software as a back door that antivirus will not flag.
- Do not delete the lure file, chat history, payment records or login alerts. The police report, the bank's stop-payment and the forensic work all need them.
- Do not contact the fraudsters, do not believe "send a small amount first and we will refund it", and do not trust anyone online offering to recover the money for you - these are standard second-stage scams.
- Do not deal only with the machine that raised the alarm. One group file is usually opened by several people and one batch of counterfeit installers reaches several departments, so check the other PCs as well.
How can I tell whether a PC has Silver Fox?
Silver Fox is a remote access trojan family descended from Gh0st RAT. It encrypts nothing and leaves no ransom note; it stays hidden and uses the victim's computer and accounts for transfer fraud. What it is, how it differs from ransomware and how its attack chain has evolved are covered on our Silver Fox threat page. This section is only about checking.
Signals ordinary staff can see - treat any one of them as a suspected infection:
- WeChat or QQ contacts disappearing or appearing on their own, groups you never created, messages marked read that you never opened;
- the "executive" or "boss" in a group suddenly using a different account and pushing for an urgent transfer or a payee change;
- login alerts from unfamiliar locations, or SMS verification codes you did not request;
- banking or brokerage activity you did not perform;
- security software switched off, refusing to open or no longer updating;
- having recently opened an archive from a new working group or an email, named around disciplinary action, personnel notices, layoffs, compensation, audits or invoices - or having installed WPS, Chrome, Sunlogin, DeepSeek, Teams or similar from a search result rather than the vendor's site.
Host and network artefacts IT can check:
| Where | What to look for |
|---|---|
| Files | A legitimately signed program loading an unexplained DLL from its own folder (for example installer.exe loading log.dll); exe, dll or dat files that should not exist in the Internet Explorer program folder or the Windows folder |
| Services and tasks | A service named UserDataSvc_ followed by random characters; scheduled tasks pointing at odd paths; newly added assemblies in the .NET Global Assembly Cache (GAC) |
| Processes | Anomalous memory injection and remote threads in explorer.exe, svchost.exe, ctfmon.exe, sihost.exe or rundll32.exe |
| Installed software | Remote-assistance, remote-control or endpoint-management tools nobody remembers installing |
| Network | Requests of the form http://[domain]:8880/ or http://[domain]:8880/getinstall64 (the call-back pattern recorded by CVERC) |
Turn on file name extensions in Windows and look again at recent files: a folder or shortcut icon on a .exe, .scr or .lnk file is almost certainly a lure. For archives or executables you are unsure about, CVERC recommends uploading them to China's national virus analysis platform (https://virus.cverc.org.cn) for testing.
One caveat matters more than the list: these signals can show that something is wrong, but finding nothing does not show that everything is fine. Silver Fox variants change quickly, and a firm conclusion needs forensics.
Which Silver Fox removal tools are genuine, and do they catch everything?
As of September 2026 we have verified that the following vendors publicly offer Silver Fox removal tools or features. Obtain them only from the vendor's own site or official channel:
| Vendor | Tool or feature | Notes |
|---|---|---|
| Huorong | Huorong Silver Fox Trojan Removal Tool | Released with a security advisory on 27 March 2025; it also removes IP-guard remote-control components from the environment |
| Sangfor | Silver Fox removal tool | Sangfor's official blog of 11 April 2025 describes it as free, with the download link provided through its official WeCom account |
| Tencent PC Manager | "Silver Fox removal" protection | The official page lists download protection, infection protection, data-theft protection and abnormal remote-access protection |
| 360 | 360 Total Security (360 Safe Guard) | 360 recommends scanning with the latest version and says it can automatically neutralise and uninstall management software that Silver Fox installed abnormally |
These tools are useful, but only in the right place in the sequence:
- Evidence before removal. What the tool deletes is exactly the sample and persistence evidence forensics needs. Where money was lost or several PCs are involved, preserve memory and disk first, then run the tool.
- A first pass, not a verdict. In December 2025 Check Point took apart the builder for ValleyRAT, the payload Silver Fox commonly uses, and found that its kernel rootkit driver automatically force-deletes dozens of security drivers on initialisation - from vendors including 360, Huorong, Tencent, Kingsoft and Kaspersky - and can hide files, directories and registry keys. A scanner may be disabled before it runs, or simply not see what is hidden.
- Legitimate management software goes unflagged. 360 has documented Silver Fox using management products such as ip-guard, Guxin endpoint security and Yangtu endpoint security for long-term persistence. These are genuine commercial products; only your own software inventory can tell you whether they belong.
- Beware fake tools. In June 2025 360 reported Silver Fox disguised as a "latest removal and protection" tool, and even distributed under the file name "Prevent Silver Fox Trojan". Never run a "removal tool" that arrived through a chat group.
A detection and a successful clean-up mean one component was found and dealt with. Whether that machine can be trusted again is a separate question.
Why rebuild a confirmed machine instead of cleaning it?
Because "it is clean now" cannot be proven, and recent Silver Fox-related variants work precisely at the kernel level. Check Point's "Cracking ValleyRAT" (December 2025) documents three things:
- Driver-level persistence. The rootkit driver installs as a kernel service named kernelquick and can switch its start type from on-demand to load at system start. It can inject shellcode from the kernel into user-mode processes and force-delete files by bypassing file locks.
- Protections do not stop it loading. Several of the drivers were not properly detected by Microsoft Defender, were absent from the latest Microsoft vulnerable driver blocklist, and still loaded on fully patched Windows 11 with HVCI and Secure Boot enabled.
- Self-concealment. The driver can hide files, directories and registry keys, so the system you inspect may not be the system that is running.
Add the other persistence shapes - silently installed legitimate management software, scheduled tasks, services, .NET GAC hijacking (see the attack chain on the threat page) - and a single miss lets the operator back in. A rebuild, by contrast, has a known cost and is often less work than proving every item clean. How to do it:
- Forensics first. A rebuild erases the basis for bounding data loss and for evidencing the case to the bank and the police.
- Copy data, not programs. Take documents, spreadsheets and images, and scan them on a clean machine first; leave behind executables, scripts, shortcuts, installers and archives of unknown origin.
- Format the system disk and install fresh. Do not restore an old system image or disk clone unless you can prove it predates the intrusion.
- Harden before going back to work. Patch, install security software, enable the Microsoft vulnerable driver blocklist, keep daily accounts off local administrator, and stop using the payment PC to receive files or run messaging apps.
A rebuild fixes one computer. Accounts, money and the other machines need handling in parallel, and if the entry point and payment process stay the same, a repeat is only a matter of time - see hardening.
How do we check the other machines in the office?
Silver Fox rarely lands on only one computer. Work from both ends at once:
Backwards from delivery. Who sent the file, into which group, how many people are in it, and who opened it? If the entry point was a counterfeit download site, find out who else downloaded software from that domain. That list is your first set of machines to examine.
Forwards from indicators. Take the hashes, landing paths, service and task names, domains and IPs extracted from the infected machine and compare every endpoint against them; search egress firewall, web-gateway and DNS logs for any other machine that contacted the same call-back address. If forensic results are not available yet, at least check each machine against the host and network artefacts listed above.
Three more checks while you are at it:
- Security tool health: which machines have protection switched off, offline or long out of date - that alone is a compromise signal;
- Remote-control and management software inventory: compare against what the company actually bought and deployed, and find the remote-assistance, remote-control and endpoint-management tools nobody claims;
- What the accounts could reach: which shares, ERP and servers the accounts used on the infected PC can access, and review those systems' login logs as well.
Vendor removal tools are fine as a first pass on each PC, but when one finds something, disconnect and report it - do not click "remove all" and reboot on the spot - so the responders can assess everything together. During the sweep, consider temporarily restricting write access from office PCs to file servers and ERP so the incident cannot widen. With many endpoints and little EDR or logging, a coordinated IOC sweep is faster and misses less.
Could ransomware follow, and when should we call in professionals?
Yes, that risk is real. Silver Fox behaves like initial access: in the campaign 360 published on 11 December 2025, the trojan went on to download and run LockBit 5.0 and encrypt files. So every file server, ERP system, database and backup the infected PC could reach needs a pre-ransomware check: has an encryptor been staged, have shadow copies been deleted, do backups still restore? The moment files start getting new extensions or a ransom note appears, switch to what to do after a ransomware attack: isolate and preserve, and do not rebuild.
Call a professional response team promptly if any of the following applies:
- money has been lost and the police and bank need technical evidence;
- the infected PC belongs to finance, the cashier, HR, IT operations or the owner, or holds credentials for servers, online banking or cloud platforms;
- more than one PC is infected, or you cannot tell how many;
- security software was switched off, removal tools fail to run, or unclaimed remote-control software turns up;
- the impersonated account has already sent messages or files to customers or suppliers, and you need to bound the data exposure and decide what to tell them;
- there are signs of encryption.
SheMo Noransom takes calls 24/7, starting remotely and coming on site when needed. Incident response handles containment, the sweep and removal; forensics produces the timeline, entry point, compromised asset list and IOCs, which can be submitted as technical material with a police report - see how to report to the police for what to prepare. Recovering funds is a legal and financial process: we support it with evidence, we do not negotiate on anyone's behalf, and we promise no outcome. The initial conversation and assessment cost nothing - contact us when you need to.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
Related solutions
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Related services
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
FAQ
Follow-up questions
Silver Fox has taken over WeChat or QQ and is messaging contacts and groups - what do we do?
First take that computer off the network so the operator loses the remote-control channel, then use your phone or another clean device to sign the desktop client out and change the password. If you are no longer sure the account is yours, WeChat lets you freeze it yourself: on the login screen tap More, open Security Center and choose to freeze the account (one tap on a trusted device); if self-service fails, request an emergency freeze through the Tencent Customer Service mini-program.
Next, phone the contacts and groups that received messages, or reach them from another account: ignore any file, link, QR code or payment request received during that period, ask group owners to remove the suspicious files, and ask anyone who opened one to disconnect and report it. Check the contact list for genuine contacts that were deleted and fake "executives" that were added. Anyone who has already paid or opened a file needs to report or check their own systems too. Keep every screenshot as evidence for the police report.
It is a home or personal PC with no IT team - how do I handle it?
The logic is the same; the steps can be simpler:
- If money went out: call 110 (or local police outside mainland China) and the bank at once, and keep the payment records and chats. Take the PC off the network without switching it off, and follow the police's instructions.
- Accounts: from your phone, change the passwords for WeChat, QQ, Alipay, online banking and mail, sign out the desktop sessions and turn on login protection.
- Data: copy documents and photos to a USB stick or external drive - no programs, installers or archives - and scan them with reputable security software on another computer.
- The PC: format the system disk, reinstall, patch it and install security software before putting the data back.
A removal tool is fine for confirmation, but a clean scan is not a substitute for reinstalling. If the PC holds work accounts or you handle payments or files for your employer, tell them as well - their systems need checking too.
Can we copy files off the infected PC, or will they carry the malware?
Usually yes, but selectively. Silver Fox does not encrypt files, so business data is normally intact. The risk is programs dressed up as files - Silver Fox lures are exactly that, an exe or lnk wearing a folder or document icon.
Turn on file name extensions first and copy only files that are clearly data (documents, spreadsheets, images, drawings). Leave behind exe, scr, lnk and bat files, scripts, installers and archives of unknown origin. Scan what you copied on a known-clean computer with current signatures before it goes onto the new system. Do not migrate saved browser passwords or whole-machine messaging-app transfers as they are; sign in again on clean devices and change the passwords. If forensics is needed, finish it before copying anything.
We legitimately use IP-guard-type management software - will it be removed, and how do we tell the difference?
It may well be removed. Huorong's Silver Fox removal tool also clears IP-guard remote-control components from the environment, and Huorong advises organisations that rely on IP-guard to use the tool with care or reinstall IP-guard afterwards. 360 has likewise documented Silver Fox using management software such as ip-guard, Guxin endpoint security and Yangtu endpoint security for persistence, and neutralises and uninstalls abnormal installations.
Tell them apart by provenance, not by product name: did your organisation buy and deploy this software, is the management server yours, do the install time and installer match your records, and does the client connect to your own management address? Anything that does not match is a back door - genuine software installed by an attacker and reporting to the attacker's console is a remote-access trojan. After the clean-up, have IT redeploy the client from your own server and take the opportunity to inventory every endpoint-management tool.
No money was lost - do we still need to report it?
We recommend reporting, or at least getting the report on record - especially if the account has been used to send scam messages or files to others. Customers or peers deceived through your account may go to the police themselves, and your own report plus the forensic findings help show the account was hijacked. Internally, tell your network administrator and the colleagues concerned, which is also what China's National Computer Virus Emergency Response Center advises.
Whether a case is opened is for the police to decide under the law. Where personal information may have leaked or sector reporting duties apply, follow the regulator and your legal counsel.
Sources
- 关于针对我国用户的「银狐」系列木马病毒攻击活动的预警报告(2026-05-21,含回连格式与「停止使用、断网、告知、改密」的处置建议)— 国家计算机病毒应急处理中心(CVERC)
- 公安部发布电信网络诈骗案件报案注意事项(记录对方账号户名、拨打 110、公安机关紧急止付)— 转载于武汉市洪山区人民政府
- 「96110」反诈骗专用号码(预警劝阻与涉诈举报)— 北京市人民政府
- 微信账号被盗紧急处理方法(安全中心冻结账号)— 腾讯客服
- 安全预警:银狐新变种突袭医疗系统,火绒发布银狐专项查杀工具(2025-03-27,工具会清除 IP-guard 远控工具)— 火绒安全
- 「银狐」病毒新变种再掀波澜?不用怕!防范措施和专杀工具请收好(2025-04-11)— 深信服
- 银狐病毒专杀(四项防护说明)— 腾讯电脑管家
- 彻底查杀顽固「银狐」木马(2024-08-29,被滥用的 ip-guard / 固信 / 阳途管理软件与「灭活」卸载)— 360
- 假安全,真木马!银狐以查杀工具之名发起钓鱼攻击(2025-06-25)— 360
- Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits(2025-12-10,kernelquick 内核服务、强制删除安全软件驱动、全补丁 Windows 11 可加载)— Check Point Research
- 银狐木马又双叒叕「进化」,远控、勒索「混合双打」发动攻击(2025-12-11,投放 LockBit 5.0)— 360
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated