logo

Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

ID: f3bf4183-0041-543e-9fb8-3890542f5bfa

STIX ID: report--f3bf4183-0041-543e-9fb8-3890542f5bfa

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**AtlasCross RAT campaign (Silver Fox)** — A Chinese-speaking-targeted campaign uses typosquatted domains impersonating trusted software brands to distribute AtlasCross RAT via trojanized Autodesk installers and ZIP lures; the malware incorporates a PowerChell execution framework, disables AMSI/ETW/ScriptBlock logging, uses ChaCha20-encrypted C2, and supports DLL injection, RDP hijacking, and persistence, while installers are signed with a stolen EV certificate and multiple delivery domains and IoCs have been identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.