Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
ID: f3bf4183-0041-543e-9fb8-3890542f5bfa
STIX ID: report--f3bf4183-0041-543e-9fb8-3890542f5bfa
Feed Name: The Hacker News
**AtlasCross RAT campaign (Silver Fox)** — A Chinese-speaking-targeted campaign uses typosquatted domains impersonating trusted software brands to distribute AtlasCross RAT via trojanized Autodesk installers and ZIP lures; the malware incorporates a PowerChell execution framework, disables AMSI/ETW/ScriptBlock logging, uses ChaCha20-encrypted C2, and supports DLL injection, RDP hijacking, and persistence, while installers are signed with a stolen EV certificate and multiple delivery domains and IoCs have been identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
