Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit
Global Security

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

AdminBy AdminJune 27, 2025No Comments3 Mins Read
Chinese Group Silver Fox Uses Fake Websites
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 27, 2025Red LakshmananMalicious software / cyber -ataka

The Chinese Silver Fox Group uses fake sites

A new company has been noted that uses fake websites that advertise popular software, such as WPS Office, Sogou and Deepseek to deliver Sainbox Rat and hidden Rootkit with open source.

Activities has been linked to the average confidence of the Chinese hacking group called A silver fox (AKA VOID ARACHNE), citing similarities in TradeCraft with previous threatening companies.

It has been revealed that phishing sites (“WPSICE (.) Com”) distribute malicious MSI installations in Chinese, indicating that the company’s goal is Chinese speakers.

“Far Loads on malicious programs include Rat Sainbox, GH0St Rats Option and Hidden Rootkit option with open source,” “Netskope Labs Labs Leandra Fros – Note.

Cybersecurity

This is not the first time the threat actor appealed to this regime. In July 2024. Esentire minute A company aimed at Chinese Windows users with fake Google Chrome sites to deliver GH0St rats.

Then earlier in February, Morphisec disclosed Another company that also used fake sites by advertising the web browser that distributed Valleyrat (AKA WINOS 4.0), another version of the GH0St rats.

Valleyrat was First documented According to ProfofPoint in September 2023 as part of a company that also highlighted users who spoke Chinese with Sainbox Rat and Purple Fox.

The Chinese Silver Fox Group uses fake sites

In the last wave of the attack, noticed by NETSKOPE, malicious MSI installations downloaded from the websites designed to launch the legal executable file called “Shine.exe”, which loads the rogue dll “Libcef.dll” using DLL loading technologies.

The main purpose of the DLL is to extract the shell from the text file (“1.Txt”), which is present in the installation, and then run it, eventually lead to other useful DLL load, remote Tajo called Sainbox.

Cybersecurity

“In the .data section analyzed, another binary PE is contained, which can be executed, depending on the configuration of malware,” Fross explained. “A built-in file is a Routkit driver based on an open source project Hidden“

While Sainbox comes with the capabilities to download additional useful loads and theft of data, hidden offers attackers array hidden features to hide malicious programs, and the Windows registry keys on the compromised hosts.

“Using options for commodity rats such as GH0St rat, and open source cores, such as hidden, giving attackers control and stealth without demanding great custom development,” Netcope said.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025

The malicious ONECLIK software is oriented

June 27, 2025

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025

The malicious ONECLIK software is oriented

June 27, 2025

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025

The new FileFix method is a threat

June 26, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.