Threat Actor Unknown origin
Void Arachne
Also known as: Silver Fox
Void Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers for AI software. They exploit public interest in VPN technology and AI software to distribute malware through SEO poisoning and Chinese-language-themed Telegram channels. The group's campaign includes bundling malicious Winos payloads with deepfake pornography-generating AI software and voice-and-face-swapping AI software. Void Arachne also promotes AI technologies for virtual kidnapping and uses AI voice-alternating technology to pressure victims into paying ransom.
Indicators of Compromise 14
Domain govtop[[.]]one Domain kkxqbh[[.]]top Filename GoFlyDrv.sys Filename Google Chrome Filename Google Chrome.exe Filename Microsoft Teams Filename Microsoft Teams.exe Filename Mixed Reality.exe Filename lllyd.jpg Filename nvdaHelperRemote.dll Filename putty Filename update.log IP 204[.]194[.]48[.]250 IP 223[.]26[.]63[.]40
MITRE ATT&CK TTPs 34
T1005 T1006 T1012 T1014 T1021 T1021.006 T1027 T1036 T1053.003 T1053.005 T1055 T1055.012 T1055.015 T1059 T1059.001 T1068 T1070.003 T1070.004 T1071 T1071.001 T1082 T1085 T1090 T1113 T1133 T1190 T1204.002 T1213 T1213.001 T1543.001 T1548 T1548.002 T1566 T1566.001
Data from Local System
Collection
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Remote Services
Lateral Movement
Windows Remote Management
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Masquerading
Defense Evasion
Cron
Execution
Scheduled Task
Execution
Process Injection
Defense Evasion
Process Hollowing
Defense Evasion
ListPlanting
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Clear Command History
Defense Evasion
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
System Information Discovery
Discovery
T1085
Proxy
Command And Control
Screen Capture
Collection
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Malicious File
Execution
Data from Information Repositories
Collection
Confluence
Collection
Launch Agent
Persistence
Abuse Elevation Control Mechanism
Privilege Escalation
Bypass User Account Control
Privilege Escalation
Phishing
Initial Access
Spearphishing Attachment
Initial Access
Source Articles
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1d ago
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
A threat actor cluster known as CylindricalCanine, linked to the broader GoldenEyeDog (APT-Q-27) group, was responsible for a breach at DigiCert in April 2026. The attackers compromised support analysts via a malicious .scr file delivered through a customer support chat, gaining access to initialization codes and stealing code-signing certificates. These certificates were then used to sign malware, including Zhong Stealer and Golden Gh0st RAT, enabling evasion of security detection. The group primarily targets finance organizations in the Asia-Pacific region using phishing and DLL side-loading techniques.
hacker-news ·1w ago
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked threat actor Silver Fox has been linked to a new Rust-based remote access trojan (RAT) named MODBEACON. This malware leverages gRPC streaming and reuses transport layers from the open-source Xray/V2Ray framework for encrypted command-and-control (C2) communications. It targets technology, education, and state-owned enterprises in Asia via counterfeit software installers distributed through SEO poisoning, enabling long-term access with capabilities including plugin loading, persistence, and data exfiltration.
hacker-news ·2w ago
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat actor is conducting a targeted cyber espionage campaign against Indian taxpayers, tax professionals, and corporate finance teams using spear-phishing emails impersonating the Indian Income Tax Department. The campaign, dubbed Operation DragonReturn, delivers DcRAT via a malicious fake tax filing utility to steal sensitive data and establish persistent access. The attackers use social engineering, DLL side-loading, image-based payload concealment, and Windows service persistence to maintain long-term access to compromised systems.
hacker-news ·3w ago