logo

Chinese Hackers Target Hospitals by Spoofing Medical Software

ID: afe8bdfd-0589-5f6c-b251-7708150c9d8c

STIX ID: report--afe8bdfd-0589-5f6c-b251-7708150c9d8c

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2025-02-27

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

A Chinese government-backed APT known as Silver Fox is distributing malicious binaries disguised as legitimate medical applications (e.g., Philips DICOM viewer) to infect patient devices with ValleyRAT, keyloggers, and cryptominers. Researchers from Vedere Labs analyzed dozens of samples (July 2024–Jan 2025) showing PowerShell-based evasion, abuse of Windows utilities, and payload retrieval from Alibaba Cloud storage; infected patient-owned devices risk introducing malware into hospital networks and expanding the group’s targeting to English-speaking regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.