Threat library · Special topic
Silver Fox Trojan
- Remote access trojan · social-engineering fraud
- Active
- Critical
Silver Fox is a remote access trojan family that has been active against Chinese organisations since 2022, tracked domestically as You She, Gudu Dadao and UTG-Q-1000 and named abroad after its payload, ValleyRAT or Winos 4.0. It descends from Gh0st RAT, whose source code leaked in 2008. It encrypts nothing: it arrives disguised as disciplinary notices, layoff compensation files, tax documents or counterfeit software installers, sits quietly on finance and HR machines, and is eventually used to impersonate an executive and authorise a fraudulent transfer - or to drop ransomware.
- Category
- Remote access trojan · social-engineering fraud
- First seen
- 2022
- Affected platforms
- Windows
- Primary targets
- Finance, cashier, expense and tax staff - the primary target / HR and administrative staff, addressed directly by "disciplinary notice" and "layoff compensation" lures / Foreign trade, e-commerce and sales staff who handle outbound payments
Topic profile
- Aliases / vendor names
- Silver Fox
- ValleyRAT
- Winos 4.0
- HoldingHands RAT
- Gh0stBins
- 游蛇
- 谷堕大盗
- UTG-Q-1000
- Void Arachne
- Category
- Remote access trojan · social-engineering fraud
- First seen
- 2022
- Affected platforms
- Windows
- Status
- Active
- Threat level
- Critical
- Primary targets
- Finance, cashier, expense and tax staff - the primary target
- HR and administrative staff, addressed directly by "disciplinary notice" and "layoff compensation" lures
- Foreign trade, e-commerce and sales staff who handle outbound payments
- Owners, legal representatives, executives and their assistants - the identity that gets impersonated
- Workstations running specialised industry software - Forescout documented samples lured as a medical image viewer
- Ordinary office endpoints whose users download software from search results
Activity timeline
China's Ministry of Public Security published five prosecuted Silver Fox cases, with 63 suspects under criminal measures in five provinces and listed per-case sums totalling over 13.4 million yuan.
SourcesCVERC's national advisory: variants posing as disciplinary lists, personnel notices and layoff rosters spread via new working groups and email, dropping a payload into the IE directory where installer.exe loads log.dll.
SourcesThreatBook reported Silver Fox resurgent in 2026: 500+ new variants in March, hundreds of shell-company domains posing as tax platforms, self-written signed drivers killing 11 security products, and user-mode unhooking.
Sources360 documented a combined remote-control and ransomware campaign: a call claiming to be from a regulator, a "complaint withdrawal" email, Silver Fox sideloaded via the Emsisoft-signed a2guard.exe, then LockBit 5.0.
SourcesCheck Point documented Silver Fox pairing WatchDog Antimalware's amsdk.sys (v1.0.600) with an older Zemana driver to cover Windows 7 through 11, with 192 security processes on its kill list, before deploying ValleyRAT.
Sources360 reported Silver Fox targeting DeepSeek local-deployment tools, re-packing counterfeit utilities or building lookalike sites. Samples log keys, watch the screen and use BYOVD to kill security software from the kernel.
SourcesForescout disclosed 29 Silver Fox samples (Jul 2024 - Jan 2025) posing as the Philips DICOM viewer; Philips was not breached. Each fetched a second stage, ran TrueSightKiller, then dropped ValleyRAT and a miner.
SourcesHuorong's Silver Fox report catalogued eight delivery routes - targeted phishing mail, fake download pages, watering-hole pages and supply chain among them - and counted victim devices in the tens of thousands per month.
SourcesCVERC advisory: a Silver Fox variant spread via phishing pages impersonating Golden Tax installers and links in WeChat groups, registering a UserDataSvc_ service for auto-start and sending host data to an overseas C2.
SourcesThreatBook named the family "Silver Fox" after a campaign pushing phishing trojans over instant messaging to finance, securities and education firms, later calling it a decentralised toolkit used by five-plus gangs.
Sources
Overview
Silver Fox is a remote access trojan (RAT) family that has been continuously active against Chinese organisations in recent years. China's National Computer Virus Emergency Response Center (CVERC), in its advisory of 21 May 2026, lists "Silver Fox" alongside "You She", "Gudu Dadao" and "UTG-Q-1000" as names for the same threat. Its payload descends from Gh0st RAT, whose source code was released publicly in 2008; researchers outside China usually name it after the payload instead, as ValleyRAT or Winos 4.0, and from 2025 a related branch called HoldingHands RAT (also tracked as Gh0stBins) appeared as well. Trend Micro named the earlier cluster that delivered Winos 4.0 through MSI installers Void Arachne - a linked designation rather than a strict synonym for what "Silver Fox" denotes in Chinese usage.
Public accounts of when it started do not agree, so we label that openly. ThreatBook formally named "Silver Fox" in March 2023 after catching a campaign; most Chinese sources describe the family as active from 2022 (the "first seen" line in the fact box above follows that reading); some trace related "You She" activity back to around 2020. We could not verify the primary material behind any of these, so we say only that it has been active in recent years rather than asserting a first-seen year.
Start with what it is not: Silver Fox is not ransomware. It encrypts nothing, renames nothing, leaves no note and demands no ransom. What it wants is to stay on the machine - watching the screen, reading chat history, learning how expenses and payments get approved - and then, at the right moment, to impersonate an executive and have finance send a payment. Because it is quiet, many organisations learn about it only after the money has left: ThreatBook wrote in April 2026 that 93.19% of the attacked companies it studied had no awareness of the compromise beforehand.
The naming disagreement is worth understanding, because it changes how you reason about the threat. ThreatBook named "Silver Fox" in March 2023 after catching a campaign that delivered phishing trojans through instant messaging to finance, securities and education organisations, and by August 2023 characterised it as a widely decentralised criminal toolkit - available to any operator, with at least five associated gangs publicly disclosed at that point. Sangfor's Qianlimu security centre, in its November 2023 report, likewise described a "Silver Fox collective" rather than a single organisation and broke it into four gang clusters. 360's 2025 annual Silver Fox report (19 January 2026) counts more than twenty crews building and re-packing the malware, with new ones still joining, and tens of thousands of attacks on Chinese government and enterprise targets over the year. Check Point, Fortinet and Kaspersky, by contrast, generally describe Silver Fox as an organised threat group (an APT) and have tracked its expansion after 2025 into Taiwan, Japan and Malaysia, and from late 2025 into India and Russia. Both readings hold together: the tooling, the evasion service and the kernel-level capability are shared, while the people using them are several unrelated crews. The practical consequence is that you should not predict the next move from a single "group profile" - assess instead who took this machine and what they intend to monetise.
Scale. Huorong reported in January 2025 that victim devices were being counted in the tens of thousands per month. China's CNCERT advisory of 22 May 2026 analysed 439 high-fidelity phishing domains distributing Silver Fox that were registered between 6 February and 4 May 2026, of which 340 (77.4%) impersonated WPS and Chrome, with the suffixes .hl.cn (42.6%) and .com.cn (30.8%) dominating; monitoring from 8 April to 7 May 2026 found up to 26,000 compromised hosts inside China at once and 182,000 infected cumulatively. On the enforcement side, the Ministry of Public Security's cyber-security bureau published five prosecuted Silver Fox cases on 16 June 2026, with 63 suspects placed under criminal measures across Jilin, Hangzhou, Shandong, Guangdong and Jiaxing; summing the per-case figures the notice gives puts the total above 13.4 million yuan, the Jilin case alone accounting for more than 7 million and 27 of the suspects.
Here is where it connects to ransomware. 360's annual report lists delivering ransomware alongside impersonation transfers, QR-code fraud and cryptocurrency theft as Silver Fox's four revenue streams, and notes that these cases typically involve ransomware crews buying a Silver-Fox-type RAT to open the door. On 11 December 2025 the company documented a campaign that opened with a "complaint withdrawal" email: once the Silver Fox trojan landed, it went on to download and run LockBit 5.0 and encrypt the machine. So "we have Silver Fox" never means "we will not be encrypted". Silver Fox behaves like initial access, and encryption is one of the options that can follow - which is why ransomware risk has to be assessed as part of any Silver Fox response.
Know what you are dealing with
How it differs from traditional ransomware
| Dimension | Traditional ransomware | Silver Fox Trojan |
|---|---|---|
| Objective | Traditional ransomwareMake data unusable and use the outage as leverage for a ransom. Being noticed is part of the plan. | Silver Fox TrojanStay unnoticed and borrow the machine, the identity and the already-signed-in accounts for as long as possible. Being noticed means failure. |
| Delivery and entry point | Traditional ransomwareEdge vulnerabilities, weak or stolen RDP and VPN credentials, exposed management panels and supply chain - with a substantial share still starting from phishing mail and malicious attachments. The centre of gravity is exposed systems and credentials. | Silver Fox TrojanFiles and links in WeChat, QQ, DingTalk and Lark groups and in email - fake disciplinary notices, layoff compensation, tax-bureau and invoice documents - plus SEO-poisoned counterfeit installers for WPS, Chrome, DeepSeek, Teams and remote-support tools. All of it comes through people. |
| Who gets hit | Traditional ransomwareServers, virtualisation platforms, databases, NAS and backup systems. IT operations normally notices first. | Silver Fox TrojanThe personal workstations of finance, HR, trade and sales staff, plus the executives whose identity gets impersonated. IT is usually the last to hear about it. |
| Visibility and dwell time | Traditional ransomwareEntry to encryption can be hours, but days to weeks is common and organised intrusions may dwell longer. Once encryption starts, though, the renamed files and the ransom note make it announce itself. | Silver Fox TrojanWeeks to months of silence, with code running inside svchost, rundll32 and other system processes. It typically surfaces only on the day of the transfer - ThreatBook reported 93.19% of attacked companies had no awareness beforehand. |
| Shape of the damage | Traditional ransomwareUnusable data, business interruption and follow-on extortion over stolen data. The loss lands on systems and compliance. | Silver Fox TrojanMoney leaves the account, credentials are stolen, identities are impersonated, and the company's contact list becomes a springboard to customers and peers. The loss lands on cash and reputation. |
| Monetisation | Traditional ransomwareA cryptocurrency ransom, negotiated around a decryption key and a promise not to publish. | Silver Fox TrojanImpersonation transfers, QR-code fraud, theft of online banking, brokerage and cryptocurrency accounts, resale of corporate financial documents and of the access itself - and dropping ransomware to earn a second time. |
| Where response effort goes | Traditional ransomwareStop writes immediately, preserve encrypted samples and the note, inventory backups and snapshots, assess recovery paths and the exfiltration scope. | Silver Fox TrojanThe first hour is stopping the money and calling the police; then isolate without powering off for memory forensics, deal with accounts and live sessions, and sweep the estate for the same payload. The files themselves usually need no recovery. |
| Can it be "recovered"? | Traditional ransomwareDepends on whether a public decryptor exists, whether backups and snapshots survived, and whether the ciphertext leaves room for structural repair - all technically assessable. | Silver Fox TrojanThe files are usually intact; "recovery" here means getting the money and the accounts back. That depends on how fast the police were called, the payment route and the bank's ability to freeze funds - a legal and financial process that technical work can evidence and support but not decide. |
Attack chain
Delivery: social engineering and counterfeit installers
Two tracks run in parallel. One is targeted social engineering: an archive dropped into a WeChat, QQ, DingTalk or Lark group - often a newly created "temporary working group" - or into email, named for a quarterly disciplinary list, a personnel notice, a layoff roster, a compensation plan or a tax inspection notice, with the icon disguised as a folder, shortcut or recycle bin (CVERC, 21 May 2026); earlier waves impersonated the Golden Tax system installer (CVERC, November 2024). The other is SEO poisoning: bulk-registered lookalike domains carrying AI-generated download pages pushed into search results - CNCERT counted 439 such domains between February and May 2026, 77.4% of them impersonating WPS and Chrome. Related campaigns have impersonated DeepSeek local-deployment tools, the Microsoft Teams installer and Philips' DICOM medical image viewer - on which Forescout stated explicitly that it has no evidence Philips or Philips devices were hacked; only the software's name and appearance were copied.
Execution: signed-binary sideloading and in-memory loading
The dropper rarely runs a malicious EXE directly. Instead a legitimately signed program sideloads a tampered DLL. The 2026 variant CVERC describes writes its payload under C:\Program Files\Internet Explorer\, where the clean installer.exe loads the key file log.dll. In the LockBit chain 360 analysed, an Emsisoft-signed a2guard.exe sideloads a rewritten sciter.dll, with the malicious code hidden in the least significant bits of image pixels. A variant Huorong reversed drops ggaa.exe, zf_cef.dll and cef.dat together. The decrypted payload is unpacked in memory and injected into system processes such as svchost.exe, ctfmon.exe, sihost.exe and rundll32.exe, leaving almost nothing suspicious on disk.
Evasion: killing AV and blinding EDR
This is where Silver Fox has invested most over the past two years. BYOVD - bring your own vulnerable driver - is the mainstay. Check Point reported on 24 February 2025 that the operators mass-produced over 2,500 variants of Truesight.sys 2.0.2 - Adlice's RogueKiller anti-rootkit driver, signed by Adlice rather than by Microsoft. Each variant altered only the eight bytes that the Authenticode hash does not cover (four in the PE optional header's CheckSum field and four in the WIN_CERTIFICATE padding at the end of the file), producing a fresh file hash while the signature still validated. It slipped past the Microsoft vulnerable driver blocklist because version 2.0.2's end-entity certificate was issued before 29 July 2015 and therefore fell under the legacy driver signing policy exception; Microsoft added that version to the blocklist on 17 December 2024. On 28 August 2025 Check Point documented abuse of WatchDog Antimalware's amsdk.sys (v1.0.600, built on the Zemana anti-malware SDK) paired with the older Zemana driver (file name zam.exe), a dual-driver design covering Windows 7 through Windows 10 and 11, with a kill list of 192 process names including mainstream Chinese products such as 360, QQ PC Manager and 2345. ThreatBook observed a further step in March 2026: rather than hunting for existing vulnerable drivers, the crews now write their own and have them legitimately signed for kernel-level confrontation, terminating 11 security products including 360, Huorong and Tencent PC Manager, while blinding EDR from user mode with unhooking. Some variants also rewrite firewall rules through COM to stop samples being uploaded for analysis.
Persistence: services, scheduled tasks and GAC hijacking
Persistence changes between builds, so a sweep has to cover several shapes at once. The 2024 variant CVERC describes registers a system service named UserDataSvc_ plus a random alphanumeric string for auto-start. A variant Huorong reversed calls services.exe over RPC to run the payload as SYSTEM and uses a COM interface to create a scheduled task pointing at an executable under C:\Windows\. The variant 360 published in August 2025 installs its DLL into the .NET Global Assembly Cache and edits the registry to take over .NET application-domain behaviour, so one foothold takes effect across managed processes. Beyond that come fileless and LOLBAS persistence, and the outright installation of legitimate remote-assistance, commercial remote-control or endpoint-management software as a back door - the kind antivirus will never flag.
Remote control and reconnaissance: screen, chat, approval flow
The implant's capabilities come from its Gh0st lineage and have been extended considerably. In "Cracking ValleyRAT", Check Point took apart the ValleyRAT / Winos 4.0 builder and found a plugin system of 38 primary plugins in matched 32-bit and 64-bit sets, covering arbitrary command execution, keylogging, credential theft, screen capture, proxying and stress-testing. Its driver plugin embeds a kernel-mode rootkit, and in some samples the signature still validates, so it loads on fully patched Windows 11 with HVCI and Secure Boot enabled. China's Ministry of Public Security, in its June 2026 notice, describes the same capability set: remote control of the computer, theft of account credentials, interception of SMS verification codes and exfiltration of private data. What the operators do with this time is not damage but study: reading WeChat and QQ history, opening finance and payroll files, learning how approvals and payments flow, who can authorise what amount, and how the boss writes.
Monetisation: impersonation transfers, account theft, ransomware
Monetisation takes several routes. The classic one is the impersonation transfer: the operator drives the victim's already-authenticated WeChat or QQ session, quietly deletes the real executive from the contact list, adds a fraud account under that person's avatar and display name, creates a "working group" and asks finance to pay a supplier, a deposit or a tax bill immediately. The five prosecutions the Ministry of Public Security published in June 2026 total more than 13.4 million yuan. Next come theft of online banking, brokerage and cryptocurrency accounts, and interception of SMS one-time codes. 360's annual report also lists ransomware delivery as a revenue stream - in the campaign it published on 11 December 2025, Silver Fox went on to download and run LockBit 5.0, which encrypts with XChaCha20 and appends a random 16-character extension.
How to identify it
Start with how it arrived. The first question is always what this machine recently installed or opened: an encrypted archive shared into a newly created working group, named around disciplinary action, personnel notices, layoffs, compensation, audits or invoices; an icon showing a folder, shortcut or recycle bin over a .exe, .scr or .lnk extension; an installer for WPS, Chrome, Sunlogin, DeepSeek or Teams downloaded from a search result rather than the vendor's site - especially from a lookalike domain.
Host artefacts. A signed-binary-plus-unknown-DLL pair is the strongest signal: a legitimately signed program such as installer.exe or a2guard.exe loading an unexplained DLL from its own directory; unexpected exe, dll or dat files under C:\Program Files\Internet Explorer\ and C:\Windows\; a system service named UserDataSvc_ followed by random characters; scheduled tasks pointing at suspicious paths; newly installed assemblies in the .NET Global Assembly Cache with matching registry edits; anomalous memory injection and remote threads in explorer.exe, svchost.exe, ctfmon.exe, sihost.exe and rundll32.exe. Also look for legitimate remote-assistance and remote-control software that nobody remembers installing - Silver Fox uses these heavily as back doors, and antivirus will not flag them.
Failures of your own security tools are evidence too. Protection switching itself off, a batch of security processes exiting shortly after a driver loads, EDR telemetry going quiet, or firewall rules rewritten so samples cannot be uploaded all point at BYOVD and user-mode unhooking.
Network and account anomalies. CVERC records call-back patterns of the form http://[domain]:8880/ and http://[domain]:8880/getinstall64, and payloads are frequently hosted on public-cloud object storage to borrow its reputation. On the account side: WeChat or QQ contacts disappearing or appearing on their own, login alerts from unfamiliar locations, messages marked read that the user never opened, an unfamiliar "executive" inside the corporate messenger, banking or brokerage activity the account holder did not perform, and SMS verification codes arriving for actions nobody initiated.
Impact and losses
The first layer is money, and it moves fast. Once the operators understand the approval chain and complete the impersonation, a transfer is often executed within tens of minutes and dispersed through layered accounts immediately afterwards. The five cases the Ministry of Public Security published in June 2026 total more than 13.4 million yuan, the largest single case exceeding 7 million. Earlier ministry notices on fraud against corporate accounting staff describe the same pattern: long dormancy, then action timed to a busy payment period. Whether funds can be recovered depends mainly on how fast the police are notified and the bank can freeze the route - a legal and financial process that technical work can evidence and support, and that nobody can promise an outcome for.
The second layer is accounts and identity. Live sessions and stored credentials for online banking, brokerage accounts, the corporate messenger, WeChat, QQ, mail and OA may all be under someone else's control, and SMS codes can be intercepted, which means second-factor confirmation is no longer trustworthy. Worse, once the company's identity is being worn by someone else, the attack travels along the contact list to customers, suppliers and peers, so one compromise can become several organisations' incident, with the legal and reputational cost that implies.
The third layer is data. Tax and finance documents, payroll, contracts, customer lists and chat archives are packaged, exfiltrated and resold to downstream fraud crews. This loss does not show up immediately, but it keeps working against you.
The fourth layer is encryption risk. Silver Fox encrypts nothing itself, but it hands an attacker a fully controlled Windows endpoint. In the campaign 360 published in December 2025, the trojan went on to download and execute LockBit 5.0. If that endpoint belongs to finance or IT operations, holds server credentials or has mapped network drives, the blast radius can extend from one workstation to file servers, ERP and databases. A Silver Fox incident therefore has to be classified as an initial-access event, not as "one PC caught a virus".
Response workflow
How SheMo Noransom responds
The first hour: stop the money and call the police
If a transfer has happened or may have happened, this comes before any technical action. Request a stop-payment and freeze immediately through corporate banking, the relationship manager and the bank's corporate hotline, and at the same time call the police (110 in China) and file a report with the local authority - only a police instruction reaches downstream accounts, and speed decides whether anything can be intercepted. We help assemble what the bank and the police will ask for: the time and amount, the recipient account and name, which endpoint and which person initiated the payment, screenshots of the impersonation and the original lure file. In parallel, freeze any payment batches not yet executed and suspend every payment confirmed only over a chat tool. Fund recovery is a legal and financial process; our role is to support and evidence it. We do not negotiate on a client's behalf and we promise no outcome.
Isolate without powering off: preserve memory
Take the affected endpoint off the network - unplug the cable, disable Wi-Fi and hotspots - but do not shut down, reboot or hibernate it. Silver Fox relies heavily on in-memory loading and process injection, so disk often holds only clean signed files while the real payload, the C2 address, the decrypted configuration and the credentials of live sessions exist only in RAM. Cutting power destroys all of it, and with it any ability to say what the attacker did or how far data went. On site we capture a memory image and volatile state first (processes, modules, network connections, injection traces, scheduled tasks, services, loaded drivers), then a forensic disk image, and all analysis happens on copies while the original is left alone. If the machine must return to service quickly, forensics still comes first - never the other way round.
Sample, C2 and delivery-channel forensics
From the memory and disk images we extract the signed-loader plus DLL pair, the injected shellcode, the decrypted configuration and the call-back addresses, and identify the variant branch and its evasion set: whether a vulnerable driver was loaded, whether EDR hooks were removed, whether legitimate remote-control software was installed as a back door. In parallel we reconstruct the delivery path - a group file, a mail attachment, or software from a counterfeit download site? Who sent it, to how many people, and who else in that group opened it? This decides two things at once: how wide the sweep must be, and which outside parties - customers, suppliers, banks, regulators - the organisation needs to notify. We hand over a checkable IOC list (hashes, landing paths, service and task names, domains, IPs and URL patterns) that the client's own EDR and endpoint management platform can apply directly.
Accounts and sessions: take the identity back
Do all of this from a clean device, never the compromised one. For WeChat, the corporate messenger, QQ, DingTalk and Lark: sign out of every device, force-terminate live sessions, change passwords and enable login protection and device locking. Then review and clean up unfamiliar contacts and groups, deleted contacts, and altered display names and avatars - and specifically verify that the "executive" in the chat is the real person. In the corporate messenger and OA, revoke anomalous session tokens, check whether approval flows were altered and whether external contacts were added. Change passwords and re-bind second factors on banking, brokerage, payment and mail accounts; until the endpoint is confirmed clean, stop treating SMS codes as sufficient proof, and ask the bank for a temporary freeze where warranted. At the same time, send one clear internal notice: impersonation fraud is active, and every payment now requires voice or in-person verification.
Estate-wide IOC sweep, removal and containment
Silver Fox rarely lands on a single machine - one group file gets opened by several people, one batch of counterfeit installers reaches several departments. Using the forensic IOCs as a baseline, we sweep the estate for matching files and hashes, anomalous signed-loader-plus-DLL pairs, UserDataSvc_-style services and suspicious scheduled tasks, unexpected assemblies in the GAC, silently installed remote-control or remote-assistance software, outbound connections and DNS requests to the C2, and suspicious driver loads. Anything found is isolated, and we check which accounts were used on those endpoints and which shares and business systems they could reach. Beyond removal, contain the spread: recall the group file, contact everyone who opened it, and temporarily restrict write access from personal workstations to file servers and ERP so the incident does not keep widening during response.
Rebuild, ransomware follow-through and rehearsal
Endpoints confirmed compromised should be rebuilt rather than cleaned: the operators held full control, and memory-resident components, legitimate remote-control back doors and self-signed drivers cannot be enumerated exhaustively, so "it is clean now" is not provable. Rebuild to a finance-workstation standard: individual accounts with least privilege, no routine use of local administrator, application allowlisting or controlled folder access, restricted reach into file servers and databases, and a dedicated payment terminal that is not used for general browsing or receiving files. Then close out the ransomware question: because Silver Fox is initial access, every server, share and backup the compromised endpoints touched has to be treated as pre-ransomware ground - check whether an encryptor was staged, whether shadow copies were deleted, whether backups still restore. If encryption does occur, our family identification, recoverability assessment and data recovery continue straight on from this engagement rather than starting over with another team. Finally, the people: run targeted training and a tabletop exercise for finance and HR, and write the rule down - every payment instruction requires voice or in-person verification, and confirmation inside a chat tool is never enough.
Risk warning
What not to do
- Do not let antivirus "clean it up" and then reboot. Silver Fox lives in memory and inside injected processes; a restart erases the payload, the C2 details and session credentials, after which nobody can establish what the attacker did or how far money and data went. Collect evidence first, remove afterwards.
- Do not keep using that machine to sign into banking, brokerage or corporate messaging, and do not change passwords on it. The operator may still be connected, and keylogging plus screen capture will hand over the new password too. Do all account work from a separate, known-clean device.
- Do not act on any transfer, payee-change or urgent-payment instruction that appears to come from an executive, owner or customer - even when the avatar, display name and writing style all match. The real account may have been quietly deleted and replaced. Verify by calling a number you already hold.
- Do not conclude the impact is limited because nothing is encrypted and the computer still works. Going unnoticed is the objective; intact files mean the implant is still on plan. Classify it as an initial-access incident and check in parallel whether ransomware is being staged.
- Do not treat only the machine that reported the problem. One group file gets opened by several people and one batch of counterfeit installers reaches several departments, so sweep the whole estate against the forensic IOCs - otherwise you clean one host while the rest keep calling home.
- Do not fix computers before reporting when money has already left. The window for a stop-payment is measured in minutes, so the police and the bank come before any technical step. And never contact the fraudsters yourself or follow a request to "send a test amount first and we will refund it" - that is a standard second-stage scam.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Prevention
Close the human entry point first. Silver Fox arrives almost entirely through messaging apps and search results, so the cheapest measures are the most effective. Download software only from vendor sites or official app stores, and prohibit installers taken from search-result download pages - of the 439 counterfeit domains CNCERT tracked, 77.4% impersonated WPS and Chrome. Treat archives in chat and email with disciplinary, notice, layoff, compensation, audit or invoice themes as suspect by default, and verify with the sender through a known channel before opening. Turn on file extensions in Windows so an .exe or .lnk wearing a folder icon is visible. And be wary of newly created "temporary working groups" - that is the standard setup move for this fraud.
Harden the payment process. This is the one control that still holds when the technical controls fail. Every instruction to transfer money, change a payee account or expedite a payment must be verified by voice or in person, with the recipient calling back a number they already hold - never a number supplied in the chat. Require dual review and thresholds for large payments. Keep the payment terminal separate from the general-purpose workstation and off messaging, browsing and file-receiving duty. Do not keep banking and brokerage access on the same machine as personal WeChat or QQ.
Control the endpoint. Ordinary users should not run as local administrator. Enable application allowlisting or controlled folder access. Deploy EDR with behavioural detection and watch for signed binaries loading unknown DLLs, anomalous process injection, unusual driver loads and newly created services and scheduled tasks. Turn on the Microsoft vulnerable driver blocklist and keep it updated, because BYOVD is the heart of this family's evasion. Forbid staff from installing remote-assistance or remote-control tools themselves, and inventory the ones already present. Centralise logs and retain them for at least six months.
Rehearse for real. Run a phishing exercise and a tabletop for finance and HR every six months, and decide in advance who to call, what to do first and which emergency number to dial - so the first hour is not spent finding people.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Aftermath
Why do we keep getting hit by ransomware, and how do we stop it for good?
Repeat infections are rarely bad luck; the previous incident was almost always left unfinished. The real entry point was never found or never closed, accounts, scheduled tasks, remote-access tools or web shells left by the attacker are still there, credentials were only partly changed, or systems were restored from backups that already contained the backdoor. Environments that paid, or whose access was resold, also get revisited. The fix follows an order: forensics to find the real entry point, a rebuild-or-clean decision, closing the entry and removing persistence, a full credential reset, then verified hardening and ongoing monitoring.
Related scenarios
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
OA Collaboration System Encrypted by Ransomware
An encrypted OA system halts document circulation, approvals, contract archives, HR and knowledge bases at once — and because OA is so often published to the internet, it is frequently the attacker's first foothold. This page covers its vulnerability profile, the twin-track recovery of attachments and database, and how to check for lateral spread.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Related industries
Financial Services Ransomware Response and Recovery
Financial and quasi-financial institutions face far stricter requirements on data integrity, transaction continuity and regulatory reporting than most sectors, so one ransomware event hits availability, customer trust and compliance simultaneously. This page covers the threat profile, a recovery approach centred on transactional consistency, and hardening priorities.
Retail and E-commerce Ransomware Response
In retail and e-commerce, ransomware translates directly into an inability to sell: order systems, membership, POS and warehouse fulfilment stop together and losses accrue by the hour. This page covers the sector's attack patterns, a recovery order built around the order-to-fulfilment chain, and handling of member data exposure.
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Related services
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
FAQ
Silver Fox Trojan Frequently asked questions
Is the Silver Fox trojan ransomware?
No. Silver Fox is a remote access trojan. It encrypts nothing, renames nothing, leaves no note and asks for no ransom. Its goal is to stay hidden long enough to learn how payments get approved - through screen capture, keylogging and chat history - and then impersonate an executive or a customer to get a transfer authorised, or to steal banking, brokerage and cryptocurrency accounts. The response logic is entirely different: a ransomware incident starts with stopping writes, preserving samples and inventorying backups, while a Silver Fox incident starts with stopping the money and calling the police, and only then moves to isolation, forensics and account recovery. But "not ransomware" is not "unrelated to ransomware" - 360's annual Silver Fox report lists ransomware delivery as one of its revenue streams.
If we have Silver Fox, will our files get encrypted?
It can happen, and there is a documented case. In the campaign 360 published on 11 December 2025, victims were lured by a "complaint withdrawal" email into opening a malicious file; once Silver Fox landed it downloaded and ran LockBit 5.0, encrypting with XChaCha20 and appending a random 16-character extension. The right way to read this is that Silver Fox behaves like initial access, and encryption is one monetisation option among several - chosen according to what the machine is worth. That is why our Silver Fox response includes a pre-ransomware sweep: whether an encryptor was staged on the servers, shares and backups the compromised endpoints touched, whether shadow copies were deleted, and whether backups still restore. If encryption does occur, our family identification, recoverability assessment and data recovery continue straight on from there.
A finance workstation is infected - what do we do first?
It depends on whether money has moved. If a transfer has happened or may have happened, call the police and the bank immediately to request a stop-payment and freeze - that window is measured in minutes and comes before any technical step - and suspend every payment batch not yet executed. If no funds have left yet, take the machine off the network (unplug the cable, disable Wi-Fi) but do not shut it down, reboot it or let antivirus clean it: Silver Fox runs largely from memory, and cutting power erases the payload, the C2 details and session credentials, leaving no way to establish what was done or what left. Third, from a separate clean device, sign out of every device on WeChat, the corporate messenger, QQ and DingTalk and change those passwords, change banking and brokerage passwords and re-bind second factors, and check for unfamiliar contacts, unfamiliar groups and deleted contacts. Fourth, notify the company: every payment instruction now requires voice or in-person verification.
How is Silver Fox removed, and is an antivirus hit enough?
An antivirus detection means one component was found, not that the machine is clean. Defeating antivirus is precisely this family's core competence: Check Point recorded over 2,500 Truesight.sys 2.0.2 variants used to slip past Microsoft's vulnerable driver blocklist (Microsoft closed that gap in December 2024 by adding the version to the list), and an amsdk.sys plus legacy Zemana dual-driver design with 192 security processes on its kill list, including mainstream Chinese products; ThreatBook observed in 2026 that the crews had moved to writing and legitimately signing their own drivers, and to blinding EDR through user-mode unhooking. Harder still, they often install legitimate remote-assistance and commercial remote-control software as a back door, which antivirus will never flag. The correct order is therefore: memory forensics first, extract IOCs, determine the variant branch and persistence method, then sweep the whole estate against those IOCs - matching files, anomalous signed-loader-plus-DLL pairs, UserDataSvc_-style services, suspicious scheduled tasks, unexpected GAC assemblies, silently installed remote-control tools and outbound connections to the C2. Endpoints confirmed compromised should be rebuilt rather than cleaned, because full control was held and "it is clean now" cannot be proven.
The transfer already went out - can the money be recovered?
There is a chance, but it depends entirely on speed and nobody can promise an outcome. Funds in this kind of fraud are dispersed through layered accounts within tens of minutes, so whether anything can be stopped comes down to whether the freeze reaches the route before the dispersal does. Call the police immediately and file locally, and contact the account bank and its corporate line to request a stop-payment - only a police instruction reaches downstream accounts. Having the following ready speeds things up materially: the time and amount, the recipient account and name, which endpoint and person initiated it, screenshots of the impersonation and the original lure file, and the forensic conclusion on how the machine was compromised. The five cases China's Ministry of Public Security published in June 2026 total more than 13.4 million yuan, which shows these cases are actively investigated - but fund recovery is a legal and financial process. Our role is evidence and support; we do not negotiate on a client's behalf and we promise no recovery rate. One more warning: never contact the fraudsters yourself, and never believe an offer to send a small amount first so the rest can be refunded - that is a standard second-stage scam.
How do we tell whether other machines are also infected?
Work backwards from delivery, then forwards from IOCs. Backwards: who sent the file, into which group, how many people were in it, and who opened it? If the entry point was a counterfeit download site, find out how many people downloaded software from that domain. Forwards: sweep the estate against the forensic IOCs for matching file hashes, unexpected exe, dll or dat files under C:\Program Files\Internet Explorer\ and C:\Windows\, UserDataSvc_-style services, scheduled tasks pointing at suspicious paths, unexpected GAC assemblies, remote-thread injection into explorer.exe, svchost.exe and similar, silently installed remote-assistance or remote-control software, and outbound connections and DNS requests to the C2 (CVERC records call-back patterns of http://[domain]:8880/ and /getinstall64). Do not overlook the health of your own security stack either: protection switched off, security processes exiting together after a driver load, or EDR telemetry going quiet are all compromise signals.
Does reinstalling Windows settle it?
It is necessary, but it solves only half the problem. Rebuilding the endpoint removes persistence; it does not bring back what already left. Credentials, chat history, tax and finance documents and customer lists may have been exfiltrated long before, and account sessions may still be in someone else's hands. So the rebuild has to happen alongside account recovery: from a clean device, sign out everywhere, change passwords, re-bind second factors and review unfamiliar and deleted contacts in the messengers. The other half is the environment. If the delivery route stays open - software still installed from search results, archives still opened straight from group chats - if the payment process is unchanged, with transfers still confirmed inside a chat tool, and if ordinary users are still local administrators, a second infection is only a matter of time. And always complete forensics before rebuilding: once the machine is wiped, the basis for bounding the data loss and for evidencing the case to the bank and the police is gone.
Sources
- 关于针对我国用户的「银狐」系列木马病毒攻击活动的预警报告(2026-05-21)— 国家计算机病毒应急处理中心(CVERC)
- 关于黑产团伙批量搭建高仿真钓鱼网站大规模传播银狐木马的风险提示(2026-05-22,含 439 个仿冒域名与 18.2 万台累计感染数据)— 国家互联网应急中心(CNCERT)
- 同上·风险提示 PDF 原文(样本分析由微步在线协助)— CNCERT
- 公安部网安局公布 5 起打击「银狐」木马病毒典型案例(2026-06-16)— 中国新闻网
- 关于针对我国用户的「银狐」木马病毒出现新变种的预警报告(仿冒金税四期 / 五期)— CVERC
- 聚焦银狐:探究病毒肆虐传播背后隐藏的迭代玄机(2025-01-15)— 火绒安全
- 2025 银狐木马年度报告(2026-01-19,把「投递勒索软件」列为获利方式之一)— 360
- 银狐木马又双叒叕「进化」,远控、勒索「混合双打」发动攻击(2025-12-11,投放 LockBit 5.0)— 360
- 「银狐」:2023 年最流行黑产工具,已至少关联 5 个团伙(2023-08,2023 年 3 月首次命名)— 微步在线
- 银狐猎影:深度揭示银狐团伙技战法(2023-11-13,提出「银狐集合体」与 4 个团伙簇)— 深信服千里目安全技术中心
- 银狐新变种于幕后潜行,暗启后门远控窃密(ggaa.exe / zf_cef.dll / cef.dat 三件套、RPC 与 COM 驻留)— 火绒安全
- 银狐木马再升级:巧妙利用 .NET 特性 GAC 劫持系统(2025-08-29)— 360
- 银狐木马针对 DeepSeek 本地化部署工具的攻击分析(2025-03)— 360
- Chasing the Silver Fox: Cat & Mouse in Kernel Shadows(2025-08-28,amsdk.sys 双驱动 BYOVD 与 192 个目标安全进程)— Check Point Research
- Healthcare Malware Hunt, Part 1: Silver Fox APT Targets Philips DICOM Viewers(2025-02-24,29 个仿冒医学影像查看器样本;Forescout 声明 Philips 本身未被入侵)— Forescout
- Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign(2025-02-24,2500+ 个 Truesight.sys 2.0.2 变种与 8 字节改法)— Check Point Research
- Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits(ValleyRAT / Winos 4.0 生成器 38 个主插件与内核 rootkit)— Check Point Research
- Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor(面向印度、俄罗斯等地的涉税钓鱼与新后门)— Kaspersky Securelist
- Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework(2024-06,Void Arachne 命名来源)— Trend Micro
- Threat Group Targets Companies in Taiwan(HoldingHands RAT / Gh0stBins 分支,仿冒台湾税务机关钓鱼)— Fortinet FortiGuard Labs
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated