logo

China's Silver Fox spoofs medical imaging apps to hijack patients' computers

ID: 38074549-48dd-576f-bc0a-dbe302df93a8

STIX ID: report--38074549-48dd-576f-bc0a-dbe302df93a8

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-02-25

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Forescout Vedere Labs found a China-linked APT (Silver Fox) distributing trojanized Philips DICOM viewers and other utilities to infect patient devices with ValleyRAT, a keylogger, and a cryptominer. Samples collected between July 2024 and January 2025 show PowerShell-based evasion, AV termination (TrueSightKiller), use of Alibaba Cloud buckets to host encrypted payloads, and C2 infrastructure activity; accessible cloud buckets and evidence of English-language and US/Canada submissions suggest expanding targeting beyond Chinese-speaking victims, posing a risk to healthcare environments and patient-owned devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.