Silver Fox APT Leverages Weaponized Medical Software to Deploy RATs and Disable AV
ID: 84a7c8c5-1715-59ab-93e1-9c689c69c427
STIX ID: report--84a7c8c5-1715-59ab-93e1-9c689c69c427
Feed Name: Cyber Press
Silver Fox (aka Void Arachne) is described as a Chinese state-sponsored APT active since 2024 that uses a trojanized Philips DICOM MediaViewerLauncher.exe to deliver a multi-stage attack: encrypted payloads retrieved from Alibaba Cloud OSS install loaders which use PowerShell Defender exclusions, scheduled tasks, and a signed but vulnerable driver (189atohci.sys) to achieve persistence and AV/EDR suppression; subsequent modules include ValleyRAT (RAT), a keylogger (credential theft), and a Monero miner, targeting healthcare, government, and critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
