Threats · 66 days ago
Silver Fox is no longer just dropping malware. It is running a reusable delivery network built around fake installers pushed through search results, so the lure can hit technology, education, and government targets at scale without a zero-day. The payload is a modular Rust RAT built for long-term access, not a one-off smash-and-grab.
QiAnXin tied the mid-June campaign to MODBEACON, a previously undocumented implant that uses plugin-style modules and encrypted gRPC streaming to CDN-hosted command infrastructure on Amazon and Cloudflare. That design makes simple domain blocking and sample-based detection less effective because the traffic looks like ordinary encrypted web use, and the same installer bait can be reused across sectors wherever users download software from the web.
1 source covering this story
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
China-linked Silver Fox deploys the Rust-based MODBEACON RAT through fake software installers, targeting technology, education, and state-owned firms.
Part of the PlainSec briefing for 2026-07-11