China's Silver Fox spoofs medical imaging apps to hijack patients' computers
ID: 38074549-48dd-576f-bc0a-dbe302df93a8
STIX ID: report--38074549-48dd-576f-bc0a-dbe302df93a8
Feed Name: The Register (Security)
Forescout Vedere Labs found a China-linked APT (Silver Fox) distributing trojanized Philips DICOM viewers and other utilities to infect patient devices with ValleyRAT, a keylogger, and a cryptominer. Samples collected between July 2024 and January 2025 show PowerShell-based evasion, AV termination (TrueSightKiller), use of Alibaba Cloud buckets to host encrypted payloads, and C2 infrastructure activity; accessible cloud buckets and evidence of English-language and US/Canada submissions suggest expanding targeting beyond Chinese-speaking victims, posing a risk to healthcare environments and patient-owned devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
