logo

Silver Fox Suspected in Taiwanese Campaign Using DeepSeek Lure

ID: a8a53d27-78c4-5607-b62e-be48d3d2b808

STIX ID: report--a8a53d27-78c4-5607-b62e-be48d3d2b808

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-07-02

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

A China-linked espionage campaign (likely Silver Fox) is distributing fake installers in Chinese that promise popular software and DeepSeek's R1 LLM to trick Taiwanese targets into running payloads. Victims receive legitimate-looking applications but also Sainbox RAT (a Gh0stRAT variant) and sometimes a Hidden rootkit; attackers leverage techniques like BYOVD and DLL sideloading for persistence and privilege escalation, with reported compromises in healthcare, government and industrial environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.