Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Threat library · Special topic

Silver Fox Trojan

  • Remote access trojan · social-engineering fraud
  • Active
  • Critical

Silver Fox is a remote access trojan family that has been active against Chinese organisations since 2022, tracked domestically as You She, Gudu Dadao and UTG-Q-1000 and named abroad after its payload, ValleyRAT or Winos 4.0. It descends from Gh0st RAT, whose source code leaked in 2008. It encrypts nothing: it arrives disguised as disciplinary notices, layoff compensation files, tax documents or counterfeit software installers, sits quietly on finance and HR machines, and is eventually used to impersonate an executive and authorise a fraudulent transfer - or to drop ransomware.

Category
Remote access trojan · social-engineering fraud
First seen
2022
Affected platforms
Windows
Primary targets
Finance, cashier, expense and tax staff - the primary target / HR and administrative staff, addressed directly by "disciplinary notice" and "layoff compensation" lures / Foreign trade, e-commerce and sales staff who handle outbound payments

Topic profile

Aliases / vendor names
  • Silver Fox
  • ValleyRAT
  • Winos 4.0
  • HoldingHands RAT
  • Gh0stBins
  • 游蛇
  • 谷堕大盗
  • UTG-Q-1000
  • Void Arachne
Category
Remote access trojan · social-engineering fraud
First seen
2022
Affected platforms
  • Windows
Status
Active
Threat level
Critical
Primary targets
  • Finance, cashier, expense and tax staff - the primary target
  • HR and administrative staff, addressed directly by "disciplinary notice" and "layoff compensation" lures
  • Foreign trade, e-commerce and sales staff who handle outbound payments
  • Owners, legal representatives, executives and their assistants - the identity that gets impersonated
  • Workstations running specialised industry software - Forescout documented samples lured as a medical image viewer
  • Ordinary office endpoints whose users download software from search results

Activity timeline

  1. China's Ministry of Public Security published five prosecuted Silver Fox cases, with 63 suspects under criminal measures in five provinces and listed per-case sums totalling over 13.4 million yuan.

    Sources
  2. CVERC's national advisory: variants posing as disciplinary lists, personnel notices and layoff rosters spread via new working groups and email, dropping a payload into the IE directory where installer.exe loads log.dll.

    Sources
  3. ThreatBook reported Silver Fox resurgent in 2026: 500+ new variants in March, hundreds of shell-company domains posing as tax platforms, self-written signed drivers killing 11 security products, and user-mode unhooking.

    Sources
  4. 360 documented a combined remote-control and ransomware campaign: a call claiming to be from a regulator, a "complaint withdrawal" email, Silver Fox sideloaded via the Emsisoft-signed a2guard.exe, then LockBit 5.0.

    Sources
  5. Check Point documented Silver Fox pairing WatchDog Antimalware's amsdk.sys (v1.0.600) with an older Zemana driver to cover Windows 7 through 11, with 192 security processes on its kill list, before deploying ValleyRAT.

    Sources
  6. 360 reported Silver Fox targeting DeepSeek local-deployment tools, re-packing counterfeit utilities or building lookalike sites. Samples log keys, watch the screen and use BYOVD to kill security software from the kernel.

    Sources
  7. Forescout disclosed 29 Silver Fox samples (Jul 2024 - Jan 2025) posing as the Philips DICOM viewer; Philips was not breached. Each fetched a second stage, ran TrueSightKiller, then dropped ValleyRAT and a miner.

    Sources
  8. Huorong's Silver Fox report catalogued eight delivery routes - targeted phishing mail, fake download pages, watering-hole pages and supply chain among them - and counted victim devices in the tens of thousands per month.

    Sources
  9. CVERC advisory: a Silver Fox variant spread via phishing pages impersonating Golden Tax installers and links in WeChat groups, registering a UserDataSvc_ service for auto-start and sending host data to an overseas C2.

    Sources
  10. ThreatBook named the family "Silver Fox" after a campaign pushing phishing trojans over instant messaging to finance, securities and education firms, later calling it a decentralised toolkit used by five-plus gangs.

    Sources

Overview

Silver Fox is a remote access trojan (RAT) family that has been continuously active against Chinese organisations in recent years. China's National Computer Virus Emergency Response Center (CVERC), in its advisory of 21 May 2026, lists "Silver Fox" alongside "You She", "Gudu Dadao" and "UTG-Q-1000" as names for the same threat. Its payload descends from Gh0st RAT, whose source code was released publicly in 2008; researchers outside China usually name it after the payload instead, as ValleyRAT or Winos 4.0, and from 2025 a related branch called HoldingHands RAT (also tracked as Gh0stBins) appeared as well. Trend Micro named the earlier cluster that delivered Winos 4.0 through MSI installers Void Arachne - a linked designation rather than a strict synonym for what "Silver Fox" denotes in Chinese usage.

Public accounts of when it started do not agree, so we label that openly. ThreatBook formally named "Silver Fox" in March 2023 after catching a campaign; most Chinese sources describe the family as active from 2022 (the "first seen" line in the fact box above follows that reading); some trace related "You She" activity back to around 2020. We could not verify the primary material behind any of these, so we say only that it has been active in recent years rather than asserting a first-seen year.

Start with what it is not: Silver Fox is not ransomware. It encrypts nothing, renames nothing, leaves no note and demands no ransom. What it wants is to stay on the machine - watching the screen, reading chat history, learning how expenses and payments get approved - and then, at the right moment, to impersonate an executive and have finance send a payment. Because it is quiet, many organisations learn about it only after the money has left: ThreatBook wrote in April 2026 that 93.19% of the attacked companies it studied had no awareness of the compromise beforehand.

The naming disagreement is worth understanding, because it changes how you reason about the threat. ThreatBook named "Silver Fox" in March 2023 after catching a campaign that delivered phishing trojans through instant messaging to finance, securities and education organisations, and by August 2023 characterised it as a widely decentralised criminal toolkit - available to any operator, with at least five associated gangs publicly disclosed at that point. Sangfor's Qianlimu security centre, in its November 2023 report, likewise described a "Silver Fox collective" rather than a single organisation and broke it into four gang clusters. 360's 2025 annual Silver Fox report (19 January 2026) counts more than twenty crews building and re-packing the malware, with new ones still joining, and tens of thousands of attacks on Chinese government and enterprise targets over the year. Check Point, Fortinet and Kaspersky, by contrast, generally describe Silver Fox as an organised threat group (an APT) and have tracked its expansion after 2025 into Taiwan, Japan and Malaysia, and from late 2025 into India and Russia. Both readings hold together: the tooling, the evasion service and the kernel-level capability are shared, while the people using them are several unrelated crews. The practical consequence is that you should not predict the next move from a single "group profile" - assess instead who took this machine and what they intend to monetise.

Scale. Huorong reported in January 2025 that victim devices were being counted in the tens of thousands per month. China's CNCERT advisory of 22 May 2026 analysed 439 high-fidelity phishing domains distributing Silver Fox that were registered between 6 February and 4 May 2026, of which 340 (77.4%) impersonated WPS and Chrome, with the suffixes .hl.cn (42.6%) and .com.cn (30.8%) dominating; monitoring from 8 April to 7 May 2026 found up to 26,000 compromised hosts inside China at once and 182,000 infected cumulatively. On the enforcement side, the Ministry of Public Security's cyber-security bureau published five prosecuted Silver Fox cases on 16 June 2026, with 63 suspects placed under criminal measures across Jilin, Hangzhou, Shandong, Guangdong and Jiaxing; summing the per-case figures the notice gives puts the total above 13.4 million yuan, the Jilin case alone accounting for more than 7 million and 27 of the suspects.

Here is where it connects to ransomware. 360's annual report lists delivering ransomware alongside impersonation transfers, QR-code fraud and cryptocurrency theft as Silver Fox's four revenue streams, and notes that these cases typically involve ransomware crews buying a Silver-Fox-type RAT to open the door. On 11 December 2025 the company documented a campaign that opened with a "complaint withdrawal" email: once the Silver Fox trojan landed, it went on to download and run LockBit 5.0 and encrypt the machine. So "we have Silver Fox" never means "we will not be encrypted". Silver Fox behaves like initial access, and encryption is one of the options that can follow - which is why ransomware risk has to be assessed as part of any Silver Fox response.

Know what you are dealing with

How it differs from traditional ransomware

ObjectiveTraditional ransomwareMake data unusable and use the outage as leverage for a ransom. Being noticed is part of the plan.Silver Fox TrojanStay unnoticed and borrow the machine, the identity and the already-signed-in accounts for as long as possible. Being noticed means failure.
Delivery and entry pointTraditional ransomwareEdge vulnerabilities, weak or stolen RDP and VPN credentials, exposed management panels and supply chain - with a substantial share still starting from phishing mail and malicious attachments. The centre of gravity is exposed systems and credentials.Silver Fox TrojanFiles and links in WeChat, QQ, DingTalk and Lark groups and in email - fake disciplinary notices, layoff compensation, tax-bureau and invoice documents - plus SEO-poisoned counterfeit installers for WPS, Chrome, DeepSeek, Teams and remote-support tools. All of it comes through people.
Who gets hitTraditional ransomwareServers, virtualisation platforms, databases, NAS and backup systems. IT operations normally notices first.Silver Fox TrojanThe personal workstations of finance, HR, trade and sales staff, plus the executives whose identity gets impersonated. IT is usually the last to hear about it.
Visibility and dwell timeTraditional ransomwareEntry to encryption can be hours, but days to weeks is common and organised intrusions may dwell longer. Once encryption starts, though, the renamed files and the ransom note make it announce itself.Silver Fox TrojanWeeks to months of silence, with code running inside svchost, rundll32 and other system processes. It typically surfaces only on the day of the transfer - ThreatBook reported 93.19% of attacked companies had no awareness beforehand.
Shape of the damageTraditional ransomwareUnusable data, business interruption and follow-on extortion over stolen data. The loss lands on systems and compliance.Silver Fox TrojanMoney leaves the account, credentials are stolen, identities are impersonated, and the company's contact list becomes a springboard to customers and peers. The loss lands on cash and reputation.
MonetisationTraditional ransomwareA cryptocurrency ransom, negotiated around a decryption key and a promise not to publish.Silver Fox TrojanImpersonation transfers, QR-code fraud, theft of online banking, brokerage and cryptocurrency accounts, resale of corporate financial documents and of the access itself - and dropping ransomware to earn a second time.
Where response effort goesTraditional ransomwareStop writes immediately, preserve encrypted samples and the note, inventory backups and snapshots, assess recovery paths and the exfiltration scope.Silver Fox TrojanThe first hour is stopping the money and calling the police; then isolate without powering off for memory forensics, deal with accounts and live sessions, and sweep the estate for the same payload. The files themselves usually need no recovery.
Can it be "recovered"?Traditional ransomwareDepends on whether a public decryptor exists, whether backups and snapshots survived, and whether the ciphertext leaves room for structural repair - all technically assessable.Silver Fox TrojanThe files are usually intact; "recovery" here means getting the money and the accounts back. That depends on how fast the police were called, the payment route and the bank's ability to freeze funds - a legal and financial process that technical work can evidence and support but not decide.

Attack chain

  1. Delivery: social engineering and counterfeit installers

    Two tracks run in parallel. One is targeted social engineering: an archive dropped into a WeChat, QQ, DingTalk or Lark group - often a newly created "temporary working group" - or into email, named for a quarterly disciplinary list, a personnel notice, a layoff roster, a compensation plan or a tax inspection notice, with the icon disguised as a folder, shortcut or recycle bin (CVERC, 21 May 2026); earlier waves impersonated the Golden Tax system installer (CVERC, November 2024). The other is SEO poisoning: bulk-registered lookalike domains carrying AI-generated download pages pushed into search results - CNCERT counted 439 such domains between February and May 2026, 77.4% of them impersonating WPS and Chrome. Related campaigns have impersonated DeepSeek local-deployment tools, the Microsoft Teams installer and Philips' DICOM medical image viewer - on which Forescout stated explicitly that it has no evidence Philips or Philips devices were hacked; only the software's name and appearance were copied.

  2. Execution: signed-binary sideloading and in-memory loading

    The dropper rarely runs a malicious EXE directly. Instead a legitimately signed program sideloads a tampered DLL. The 2026 variant CVERC describes writes its payload under C:\Program Files\Internet Explorer\, where the clean installer.exe loads the key file log.dll. In the LockBit chain 360 analysed, an Emsisoft-signed a2guard.exe sideloads a rewritten sciter.dll, with the malicious code hidden in the least significant bits of image pixels. A variant Huorong reversed drops ggaa.exe, zf_cef.dll and cef.dat together. The decrypted payload is unpacked in memory and injected into system processes such as svchost.exe, ctfmon.exe, sihost.exe and rundll32.exe, leaving almost nothing suspicious on disk.

  3. Evasion: killing AV and blinding EDR

    This is where Silver Fox has invested most over the past two years. BYOVD - bring your own vulnerable driver - is the mainstay. Check Point reported on 24 February 2025 that the operators mass-produced over 2,500 variants of Truesight.sys 2.0.2 - Adlice's RogueKiller anti-rootkit driver, signed by Adlice rather than by Microsoft. Each variant altered only the eight bytes that the Authenticode hash does not cover (four in the PE optional header's CheckSum field and four in the WIN_CERTIFICATE padding at the end of the file), producing a fresh file hash while the signature still validated. It slipped past the Microsoft vulnerable driver blocklist because version 2.0.2's end-entity certificate was issued before 29 July 2015 and therefore fell under the legacy driver signing policy exception; Microsoft added that version to the blocklist on 17 December 2024. On 28 August 2025 Check Point documented abuse of WatchDog Antimalware's amsdk.sys (v1.0.600, built on the Zemana anti-malware SDK) paired with the older Zemana driver (file name zam.exe), a dual-driver design covering Windows 7 through Windows 10 and 11, with a kill list of 192 process names including mainstream Chinese products such as 360, QQ PC Manager and 2345. ThreatBook observed a further step in March 2026: rather than hunting for existing vulnerable drivers, the crews now write their own and have them legitimately signed for kernel-level confrontation, terminating 11 security products including 360, Huorong and Tencent PC Manager, while blinding EDR from user mode with unhooking. Some variants also rewrite firewall rules through COM to stop samples being uploaded for analysis.

  4. Persistence: services, scheduled tasks and GAC hijacking

    Persistence changes between builds, so a sweep has to cover several shapes at once. The 2024 variant CVERC describes registers a system service named UserDataSvc_ plus a random alphanumeric string for auto-start. A variant Huorong reversed calls services.exe over RPC to run the payload as SYSTEM and uses a COM interface to create a scheduled task pointing at an executable under C:\Windows\. The variant 360 published in August 2025 installs its DLL into the .NET Global Assembly Cache and edits the registry to take over .NET application-domain behaviour, so one foothold takes effect across managed processes. Beyond that come fileless and LOLBAS persistence, and the outright installation of legitimate remote-assistance, commercial remote-control or endpoint-management software as a back door - the kind antivirus will never flag.

  5. Remote control and reconnaissance: screen, chat, approval flow

    The implant's capabilities come from its Gh0st lineage and have been extended considerably. In "Cracking ValleyRAT", Check Point took apart the ValleyRAT / Winos 4.0 builder and found a plugin system of 38 primary plugins in matched 32-bit and 64-bit sets, covering arbitrary command execution, keylogging, credential theft, screen capture, proxying and stress-testing. Its driver plugin embeds a kernel-mode rootkit, and in some samples the signature still validates, so it loads on fully patched Windows 11 with HVCI and Secure Boot enabled. China's Ministry of Public Security, in its June 2026 notice, describes the same capability set: remote control of the computer, theft of account credentials, interception of SMS verification codes and exfiltration of private data. What the operators do with this time is not damage but study: reading WeChat and QQ history, opening finance and payroll files, learning how approvals and payments flow, who can authorise what amount, and how the boss writes.

  6. Monetisation: impersonation transfers, account theft, ransomware

    Monetisation takes several routes. The classic one is the impersonation transfer: the operator drives the victim's already-authenticated WeChat or QQ session, quietly deletes the real executive from the contact list, adds a fraud account under that person's avatar and display name, creates a "working group" and asks finance to pay a supplier, a deposit or a tax bill immediately. The five prosecutions the Ministry of Public Security published in June 2026 total more than 13.4 million yuan. Next come theft of online banking, brokerage and cryptocurrency accounts, and interception of SMS one-time codes. 360's annual report also lists ransomware delivery as a revenue stream - in the campaign it published on 11 December 2025, Silver Fox went on to download and run LockBit 5.0, which encrypts with XChaCha20 and appends a random 16-character extension.

How to identify it

Start with how it arrived. The first question is always what this machine recently installed or opened: an encrypted archive shared into a newly created working group, named around disciplinary action, personnel notices, layoffs, compensation, audits or invoices; an icon showing a folder, shortcut or recycle bin over a .exe, .scr or .lnk extension; an installer for WPS, Chrome, Sunlogin, DeepSeek or Teams downloaded from a search result rather than the vendor's site - especially from a lookalike domain.

Host artefacts. A signed-binary-plus-unknown-DLL pair is the strongest signal: a legitimately signed program such as installer.exe or a2guard.exe loading an unexplained DLL from its own directory; unexpected exe, dll or dat files under C:\Program Files\Internet Explorer\ and C:\Windows\; a system service named UserDataSvc_ followed by random characters; scheduled tasks pointing at suspicious paths; newly installed assemblies in the .NET Global Assembly Cache with matching registry edits; anomalous memory injection and remote threads in explorer.exe, svchost.exe, ctfmon.exe, sihost.exe and rundll32.exe. Also look for legitimate remote-assistance and remote-control software that nobody remembers installing - Silver Fox uses these heavily as back doors, and antivirus will not flag them.

Failures of your own security tools are evidence too. Protection switching itself off, a batch of security processes exiting shortly after a driver loads, EDR telemetry going quiet, or firewall rules rewritten so samples cannot be uploaded all point at BYOVD and user-mode unhooking.

Network and account anomalies. CVERC records call-back patterns of the form http://[domain]:8880/ and http://[domain]:8880/getinstall64, and payloads are frequently hosted on public-cloud object storage to borrow its reputation. On the account side: WeChat or QQ contacts disappearing or appearing on their own, login alerts from unfamiliar locations, messages marked read that the user never opened, an unfamiliar "executive" inside the corporate messenger, banking or brokerage activity the account holder did not perform, and SMS verification codes arriving for actions nobody initiated.

Impact and losses

The first layer is money, and it moves fast. Once the operators understand the approval chain and complete the impersonation, a transfer is often executed within tens of minutes and dispersed through layered accounts immediately afterwards. The five cases the Ministry of Public Security published in June 2026 total more than 13.4 million yuan, the largest single case exceeding 7 million. Earlier ministry notices on fraud against corporate accounting staff describe the same pattern: long dormancy, then action timed to a busy payment period. Whether funds can be recovered depends mainly on how fast the police are notified and the bank can freeze the route - a legal and financial process that technical work can evidence and support, and that nobody can promise an outcome for.

The second layer is accounts and identity. Live sessions and stored credentials for online banking, brokerage accounts, the corporate messenger, WeChat, QQ, mail and OA may all be under someone else's control, and SMS codes can be intercepted, which means second-factor confirmation is no longer trustworthy. Worse, once the company's identity is being worn by someone else, the attack travels along the contact list to customers, suppliers and peers, so one compromise can become several organisations' incident, with the legal and reputational cost that implies.

The third layer is data. Tax and finance documents, payroll, contracts, customer lists and chat archives are packaged, exfiltrated and resold to downstream fraud crews. This loss does not show up immediately, but it keeps working against you.

The fourth layer is encryption risk. Silver Fox encrypts nothing itself, but it hands an attacker a fully controlled Windows endpoint. In the campaign 360 published in December 2025, the trojan went on to download and execute LockBit 5.0. If that endpoint belongs to finance or IT operations, holds server credentials or has mapped network drives, the blast radius can extend from one workstation to file servers, ERP and databases. A Silver Fox incident therefore has to be classified as an initial-access event, not as "one PC caught a virus".

Response workflow

How SheMo Noransom responds

  1. The first hour: stop the money and call the police

    If a transfer has happened or may have happened, this comes before any technical action. Request a stop-payment and freeze immediately through corporate banking, the relationship manager and the bank's corporate hotline, and at the same time call the police (110 in China) and file a report with the local authority - only a police instruction reaches downstream accounts, and speed decides whether anything can be intercepted. We help assemble what the bank and the police will ask for: the time and amount, the recipient account and name, which endpoint and which person initiated the payment, screenshots of the impersonation and the original lure file. In parallel, freeze any payment batches not yet executed and suspend every payment confirmed only over a chat tool. Fund recovery is a legal and financial process; our role is to support and evidence it. We do not negotiate on a client's behalf and we promise no outcome.

  2. Isolate without powering off: preserve memory

    Take the affected endpoint off the network - unplug the cable, disable Wi-Fi and hotspots - but do not shut down, reboot or hibernate it. Silver Fox relies heavily on in-memory loading and process injection, so disk often holds only clean signed files while the real payload, the C2 address, the decrypted configuration and the credentials of live sessions exist only in RAM. Cutting power destroys all of it, and with it any ability to say what the attacker did or how far data went. On site we capture a memory image and volatile state first (processes, modules, network connections, injection traces, scheduled tasks, services, loaded drivers), then a forensic disk image, and all analysis happens on copies while the original is left alone. If the machine must return to service quickly, forensics still comes first - never the other way round.

  3. Sample, C2 and delivery-channel forensics

    From the memory and disk images we extract the signed-loader plus DLL pair, the injected shellcode, the decrypted configuration and the call-back addresses, and identify the variant branch and its evasion set: whether a vulnerable driver was loaded, whether EDR hooks were removed, whether legitimate remote-control software was installed as a back door. In parallel we reconstruct the delivery path - a group file, a mail attachment, or software from a counterfeit download site? Who sent it, to how many people, and who else in that group opened it? This decides two things at once: how wide the sweep must be, and which outside parties - customers, suppliers, banks, regulators - the organisation needs to notify. We hand over a checkable IOC list (hashes, landing paths, service and task names, domains, IPs and URL patterns) that the client's own EDR and endpoint management platform can apply directly.

  4. Accounts and sessions: take the identity back

    Do all of this from a clean device, never the compromised one. For WeChat, the corporate messenger, QQ, DingTalk and Lark: sign out of every device, force-terminate live sessions, change passwords and enable login protection and device locking. Then review and clean up unfamiliar contacts and groups, deleted contacts, and altered display names and avatars - and specifically verify that the "executive" in the chat is the real person. In the corporate messenger and OA, revoke anomalous session tokens, check whether approval flows were altered and whether external contacts were added. Change passwords and re-bind second factors on banking, brokerage, payment and mail accounts; until the endpoint is confirmed clean, stop treating SMS codes as sufficient proof, and ask the bank for a temporary freeze where warranted. At the same time, send one clear internal notice: impersonation fraud is active, and every payment now requires voice or in-person verification.

  5. Estate-wide IOC sweep, removal and containment

    Silver Fox rarely lands on a single machine - one group file gets opened by several people, one batch of counterfeit installers reaches several departments. Using the forensic IOCs as a baseline, we sweep the estate for matching files and hashes, anomalous signed-loader-plus-DLL pairs, UserDataSvc_-style services and suspicious scheduled tasks, unexpected assemblies in the GAC, silently installed remote-control or remote-assistance software, outbound connections and DNS requests to the C2, and suspicious driver loads. Anything found is isolated, and we check which accounts were used on those endpoints and which shares and business systems they could reach. Beyond removal, contain the spread: recall the group file, contact everyone who opened it, and temporarily restrict write access from personal workstations to file servers and ERP so the incident does not keep widening during response.

  6. Rebuild, ransomware follow-through and rehearsal

    Endpoints confirmed compromised should be rebuilt rather than cleaned: the operators held full control, and memory-resident components, legitimate remote-control back doors and self-signed drivers cannot be enumerated exhaustively, so "it is clean now" is not provable. Rebuild to a finance-workstation standard: individual accounts with least privilege, no routine use of local administrator, application allowlisting or controlled folder access, restricted reach into file servers and databases, and a dedicated payment terminal that is not used for general browsing or receiving files. Then close out the ransomware question: because Silver Fox is initial access, every server, share and backup the compromised endpoints touched has to be treated as pre-ransomware ground - check whether an encryptor was staged, whether shadow copies were deleted, whether backups still restore. If encryption does occur, our family identification, recoverability assessment and data recovery continue straight on from this engagement rather than starting over with another team. Finally, the people: run targeted training and a tabletop exercise for finance and HR, and write the rule down - every payment instruction requires voice or in-person verification, and confirmation inside a chat tool is never enough.

Risk warning

What not to do

  • Do not let antivirus "clean it up" and then reboot. Silver Fox lives in memory and inside injected processes; a restart erases the payload, the C2 details and session credentials, after which nobody can establish what the attacker did or how far money and data went. Collect evidence first, remove afterwards.
  • Do not keep using that machine to sign into banking, brokerage or corporate messaging, and do not change passwords on it. The operator may still be connected, and keylogging plus screen capture will hand over the new password too. Do all account work from a separate, known-clean device.
  • Do not act on any transfer, payee-change or urgent-payment instruction that appears to come from an executive, owner or customer - even when the avatar, display name and writing style all match. The real account may have been quietly deleted and replaced. Verify by calling a number you already hold.
  • Do not conclude the impact is limited because nothing is encrypted and the computer still works. Going unnoticed is the objective; intact files mean the implant is still on plan. Classify it as an initial-access incident and check in parallel whether ransomware is being staged.
  • Do not treat only the machine that reported the problem. One group file gets opened by several people and one batch of counterfeit installers reaches several departments, so sweep the whole estate against the forensic IOCs - otherwise you clean one host while the rest keep calling home.
  • Do not fix computers before reporting when money has already left. The window for a stop-payment is measured in minutes, so the police and the bank come before any technical step. And never contact the fraudsters yourself or follow a request to "send a test amount first and we will refund it" - that is a standard second-stage scam.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Prevention

Close the human entry point first. Silver Fox arrives almost entirely through messaging apps and search results, so the cheapest measures are the most effective. Download software only from vendor sites or official app stores, and prohibit installers taken from search-result download pages - of the 439 counterfeit domains CNCERT tracked, 77.4% impersonated WPS and Chrome. Treat archives in chat and email with disciplinary, notice, layoff, compensation, audit or invoice themes as suspect by default, and verify with the sender through a known channel before opening. Turn on file extensions in Windows so an .exe or .lnk wearing a folder icon is visible. And be wary of newly created "temporary working groups" - that is the standard setup move for this fraud.

Harden the payment process. This is the one control that still holds when the technical controls fail. Every instruction to transfer money, change a payee account or expedite a payment must be verified by voice or in person, with the recipient calling back a number they already hold - never a number supplied in the chat. Require dual review and thresholds for large payments. Keep the payment terminal separate from the general-purpose workstation and off messaging, browsing and file-receiving duty. Do not keep banking and brokerage access on the same machine as personal WeChat or QQ.

Control the endpoint. Ordinary users should not run as local administrator. Enable application allowlisting or controlled folder access. Deploy EDR with behavioural detection and watch for signed binaries loading unknown DLLs, anomalous process injection, unusual driver loads and newly created services and scheduled tasks. Turn on the Microsoft vulnerable driver blocklist and keep it updated, because BYOVD is the heart of this family's evasion. Forbid staff from installing remote-assistance or remote-control tools themselves, and inventory the ones already present. Centralise logs and retain them for at least six months.

Rehearse for real. Run a phishing exercise and a tabletop for finance and HR every six months, and decide in advance who to call, what to do first and which emergency number to dial - so the first hour is not spent finding people.

Related questions

Related scenarios

Related industries

FAQ

Silver Fox Trojan Frequently asked questions

  • Is the Silver Fox trojan ransomware?

    No. Silver Fox is a remote access trojan. It encrypts nothing, renames nothing, leaves no note and asks for no ransom. Its goal is to stay hidden long enough to learn how payments get approved - through screen capture, keylogging and chat history - and then impersonate an executive or a customer to get a transfer authorised, or to steal banking, brokerage and cryptocurrency accounts. The response logic is entirely different: a ransomware incident starts with stopping writes, preserving samples and inventorying backups, while a Silver Fox incident starts with stopping the money and calling the police, and only then moves to isolation, forensics and account recovery. But "not ransomware" is not "unrelated to ransomware" - 360's annual Silver Fox report lists ransomware delivery as one of its revenue streams.

  • If we have Silver Fox, will our files get encrypted?

    It can happen, and there is a documented case. In the campaign 360 published on 11 December 2025, victims were lured by a "complaint withdrawal" email into opening a malicious file; once Silver Fox landed it downloaded and ran LockBit 5.0, encrypting with XChaCha20 and appending a random 16-character extension. The right way to read this is that Silver Fox behaves like initial access, and encryption is one monetisation option among several - chosen according to what the machine is worth. That is why our Silver Fox response includes a pre-ransomware sweep: whether an encryptor was staged on the servers, shares and backups the compromised endpoints touched, whether shadow copies were deleted, and whether backups still restore. If encryption does occur, our family identification, recoverability assessment and data recovery continue straight on from there.

  • A finance workstation is infected - what do we do first?

    It depends on whether money has moved. If a transfer has happened or may have happened, call the police and the bank immediately to request a stop-payment and freeze - that window is measured in minutes and comes before any technical step - and suspend every payment batch not yet executed. If no funds have left yet, take the machine off the network (unplug the cable, disable Wi-Fi) but do not shut it down, reboot it or let antivirus clean it: Silver Fox runs largely from memory, and cutting power erases the payload, the C2 details and session credentials, leaving no way to establish what was done or what left. Third, from a separate clean device, sign out of every device on WeChat, the corporate messenger, QQ and DingTalk and change those passwords, change banking and brokerage passwords and re-bind second factors, and check for unfamiliar contacts, unfamiliar groups and deleted contacts. Fourth, notify the company: every payment instruction now requires voice or in-person verification.

  • How is Silver Fox removed, and is an antivirus hit enough?

    An antivirus detection means one component was found, not that the machine is clean. Defeating antivirus is precisely this family's core competence: Check Point recorded over 2,500 Truesight.sys 2.0.2 variants used to slip past Microsoft's vulnerable driver blocklist (Microsoft closed that gap in December 2024 by adding the version to the list), and an amsdk.sys plus legacy Zemana dual-driver design with 192 security processes on its kill list, including mainstream Chinese products; ThreatBook observed in 2026 that the crews had moved to writing and legitimately signing their own drivers, and to blinding EDR through user-mode unhooking. Harder still, they often install legitimate remote-assistance and commercial remote-control software as a back door, which antivirus will never flag. The correct order is therefore: memory forensics first, extract IOCs, determine the variant branch and persistence method, then sweep the whole estate against those IOCs - matching files, anomalous signed-loader-plus-DLL pairs, UserDataSvc_-style services, suspicious scheduled tasks, unexpected GAC assemblies, silently installed remote-control tools and outbound connections to the C2. Endpoints confirmed compromised should be rebuilt rather than cleaned, because full control was held and "it is clean now" cannot be proven.

  • The transfer already went out - can the money be recovered?

    There is a chance, but it depends entirely on speed and nobody can promise an outcome. Funds in this kind of fraud are dispersed through layered accounts within tens of minutes, so whether anything can be stopped comes down to whether the freeze reaches the route before the dispersal does. Call the police immediately and file locally, and contact the account bank and its corporate line to request a stop-payment - only a police instruction reaches downstream accounts. Having the following ready speeds things up materially: the time and amount, the recipient account and name, which endpoint and person initiated it, screenshots of the impersonation and the original lure file, and the forensic conclusion on how the machine was compromised. The five cases China's Ministry of Public Security published in June 2026 total more than 13.4 million yuan, which shows these cases are actively investigated - but fund recovery is a legal and financial process. Our role is evidence and support; we do not negotiate on a client's behalf and we promise no recovery rate. One more warning: never contact the fraudsters yourself, and never believe an offer to send a small amount first so the rest can be refunded - that is a standard second-stage scam.

  • How do we tell whether other machines are also infected?

    Work backwards from delivery, then forwards from IOCs. Backwards: who sent the file, into which group, how many people were in it, and who opened it? If the entry point was a counterfeit download site, find out how many people downloaded software from that domain. Forwards: sweep the estate against the forensic IOCs for matching file hashes, unexpected exe, dll or dat files under C:\Program Files\Internet Explorer\ and C:\Windows\, UserDataSvc_-style services, scheduled tasks pointing at suspicious paths, unexpected GAC assemblies, remote-thread injection into explorer.exe, svchost.exe and similar, silently installed remote-assistance or remote-control software, and outbound connections and DNS requests to the C2 (CVERC records call-back patterns of http://[domain]:8880/ and /getinstall64). Do not overlook the health of your own security stack either: protection switched off, security processes exiting together after a driver load, or EDR telemetry going quiet are all compromise signals.

  • Does reinstalling Windows settle it?

    It is necessary, but it solves only half the problem. Rebuilding the endpoint removes persistence; it does not bring back what already left. Credentials, chat history, tax and finance documents and customer lists may have been exfiltrated long before, and account sessions may still be in someone else's hands. So the rebuild has to happen alongside account recovery: from a clean device, sign out everywhere, change passwords, re-bind second factors and review unfamiliar and deleted contacts in the messengers. The other half is the environment. If the delivery route stays open - software still installed from search results, archives still opened straight from group chats - if the payment process is unchanged, with transfers still confirmed inside a chat tool, and if ordinary users are still local administrators, a second infection is only a matter of time. And always complete forensics before rebuilding: once the machine is wiped, the basis for bounding the data loss and for evidencing the case to the bank and the police is gone.

Sources

External links are provided for reference only. The content is published by third parties and does not represent our position.

Updated