Silver Fox Suspected in Taiwanese Campaign Using DeepSeek Lure
ID: a8a53d27-78c4-5607-b62e-be48d3d2b808
STIX ID: report--a8a53d27-78c4-5607-b62e-be48d3d2b808
Feed Name: Dark Reading
A China-linked espionage campaign (likely Silver Fox) is distributing fake installers in Chinese that promise popular software and DeepSeek's R1 LLM to trick Taiwanese targets into running payloads. Victims receive legitimate-looking applications but also Sainbox RAT (a Gh0stRAT variant) and sometimes a Hidden rootkit; attackers leverage techniques like BYOVD and DLL sideloading for persistence and privilege escalation, with reported compromises in healthcare, government and industrial environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
