Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silver Fox Intensifies Asia Cyber Campaign with New Trojan

Silver Fox Intensifies Asia Cyber Campaign with New Trojan

Posted on March 31, 2026 By CWS

An ongoing cyber campaign has been identified targeting Chinese-speaking individuals through typosquatted domains mimicking well-known software brands. This campaign aims to distribute a newly detected remote access trojan (RAT) called AtlasCross. According to Germany-based cybersecurity firm Hexastrike, the operation leverages fake domains that emulate brands such as Surfshark VPN, Signal, and Microsoft Teams, among others.

Details of the Cyber Campaign

This malicious activity is linked to a Chinese cybercrime group known as Silver Fox, also referred to by multiple aliases including SwimSnake and Void Arachne. Silver Fox’s latest efforts involve tricking users into downloading compromised software packages that contain the AtlasCross RAT. These packages often masquerade as legitimate applications, luring users into a false sense of security.

The operation employs a sophisticated delivery mechanism, utilizing fake websites to ensnare users. Once a user downloads the infected package, it installs a compromised version of an application, which then executes a shellcode loader. This loader retrieves command-and-control configurations to facilitate the RAT’s deployment, leading to unauthorized access and control over the victim’s system.

Technical Insights and Strategy

A significant element of this campaign is the use of a stolen Extended Validation code-signing certificate, originally issued to a Vietnamese company. This certificate has been exploited in various unrelated malware operations, suggesting its widespread misuse in the cybercrime landscape. The AtlasCross RAT integrates the PowerChell framework, enhancing its ability to execute commands while evading detection by disabling key security features.

Silver Fox’s strategy involves highly mimicking official domains, employing techniques like typo-squatting and DNS manipulation to enhance credibility and reduce suspicion. This multi-faceted approach has enabled the group to conduct operations across multiple Asian countries, including Japan, Malaysia, and India, since late 2025.

Implications and Future Outlook

Silver Fox has been characterized as a prominent cyber threat, targeting various sectors with advanced tools and techniques. The group’s dual-track operational model, which balances broad cyber campaigns with targeted attacks, demonstrates its adaptability and persistence. As cyber threats continue to evolve, organizations in the region must bolster their defenses and remain vigilant against such sophisticated attacks.

The ongoing developments in Silver Fox’s cyber activities highlight the need for continuous monitoring and updated security measures. As the group refines its tactics, the potential for widespread disruption and data theft increases, necessitating proactive cybersecurity strategies from both private and public sectors to mitigate risks.

The Hacker News Tags:Asia, AtlasCross RAT, China, cyber attack, Cybersecurity, fake domains, Gh0st RAT, Hexastrike, Malware, Phishing, remote access trojan, Silver Fox, typosquatting, ValleyRAT

Post navigation

Previous Post: Google Launches Ransomware Protection for Drive
Next Post: Exploitation of Fortinet FortiClient Vulnerability Begins

Related Posts

China-Linked Group Uses BPFDoor to Spy on Telecoms China-Linked Group Uses BPFDoor to Spy on Telecoms The Hacker News
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution The Hacker News
Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
Microsoft Helps CBI Dismantle Indian Call Centers Behind Japanese Tech Support Scam Microsoft Helps CBI Dismantle Indian Call Centers Behind Japanese Tech Support Scam The Hacker News
Russian Arrests LeakBase Admin in Major Cybercrime Bust Russian Arrests LeakBase Admin in Major Cybercrime Bust The Hacker News
AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before Takedown AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Big Tech Challenges Canadian Encryption Bill Amidst Security Concerns
  • Microsoft Warns of Attacks via HPE Operations Agent
  • Hackers Exploit OrBit Rootkit to Steal Linux Credentials
  • OpenAI Addresses TanStack Supply Chain Breach
  • OpenAI Faces Supply Chain Cyberattack: macOS Updates Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Big Tech Challenges Canadian Encryption Bill Amidst Security Concerns
  • Microsoft Warns of Attacks via HPE Operations Agent
  • Hackers Exploit OrBit Rootkit to Steal Linux Credentials
  • OpenAI Addresses TanStack Supply Chain Breach
  • OpenAI Faces Supply Chain Cyberattack: macOS Updates Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark