Threats · 168 days ago
Silver Fox delivered a new bespoke remote access trojan called AtlasCross RAT to Chinese-speaking users. The group used 11 typosquatted sites impersonating VPNs, messengers, conferencing and e‑commerce brands to lure victims into trojanised installers. The installer drops a trojanised Autodesk binary that loads shellcode, extracts C2 details, and fetches a second‑stage payload from bifa668[.]com to run AtlasCross in memory. Researchers say this represents a shift from the group's prior use of Gh0st RAT derivatives to a custom, persistent payload aimed at targets in Asia.
1 source covering this story
Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
AtlasCross RAT spreads via 11 fake domains registered October 27, 2025, enabling encrypted C2 control and persistence.
Part of the PlainSec briefing for 2026-03-31