logo

Silver Fox APT Leverages Weaponized Medical Software to Deploy RATs and Disable AV

ID: 84a7c8c5-1715-59ab-93e1-9c689c69c427

STIX ID: report--84a7c8c5-1715-59ab-93e1-9c689c69c427

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-06-19

Date Updated: 2026-04-13

Author: Mandvi

...
...

Silver Fox (aka Void Arachne) is described as a Chinese state-sponsored APT active since 2024 that uses a trojanized Philips DICOM MediaViewerLauncher.exe to deliver a multi-stage attack: encrypted payloads retrieved from Alibaba Cloud OSS install loaders which use PowerShell Defender exclusions, scheduled tasks, and a signed but vulnerable driver (189atohci.sys) to achieve persistence and AV/EDR suppression; subsequent modules include ValleyRAT (RAT), a keylogger (credential theft), and a Monero miner, targeting healthcare, government, and critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.