Chinese Hackers Target Hospitals by Spoofing Medical Software
ID: afe8bdfd-0589-5f6c-b251-7708150c9d8c
STIX ID: report--afe8bdfd-0589-5f6c-b251-7708150c9d8c
Feed Name: KnowBe4 Blog
A Chinese government-backed APT known as Silver Fox is distributing malicious binaries disguised as legitimate medical applications (e.g., Philips DICOM viewer) to infect patient devices with ValleyRAT, keyloggers, and cryptominers. Researchers from Vedere Labs analyzed dozens of samples (July 2024–Jan 2025) showing PowerShell-based evasion, abuse of Windows utilities, and payload retrieval from Alibaba Cloud storage; infected patient-owned devices risk introducing malware into hospital networks and expanding the group’s targeting to English-speaking regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
