logo

Chinese-Backed Silver Fox Plants Backdoors in Healthcare Networks

ID: cbcc02a5-1e1a-576f-ab59-0d637dcdc7a6

STIX ID: report--cbcc02a5-1e1a-576f-ab59-0d637dcdc7a6

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-02-25

Date Updated: 2026-04-22

...
...

**Silver Fox targets healthcare imaging software:** Researchers observed a multi-stage campaign where the Silver Fox group distributed malicious installers masquerading as Philips DICOM viewers to deploy ValleyRAT backdoors, keyloggers and crypto miners via encrypted payloads hosted in cloud buckets, using extensive evasion, persistence and AV/EDR termination techniques; the report includes sample timelines, actor history and mitigation guidance for healthcare organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.