Silver Fox Uses Typosquats to Deliver AtlasCross RAT

Silver Fox delivered a new bespoke remote access trojan called AtlasCross RAT to Chinese-speaking users. The group used 11 typosquatted sites impersonating VPNs, messengers, conferencing and e‑commerce brands to lure victims into trojanised installers. The installer drops a trojanised Autodesk binary that loads shellcode, extracts C2 details, and fetches a second‑stage payload from bifa668[.]com to run AtlasCross in memory. Researchers say this represents a shift from the group's prior use of Gh0st RAT derivatives to a custom, persistent payload aimed at targets in Asia.

Part of the PlainSec briefing for 2026-03-31

Sources