Fake Installers Strike Again: Silver Fox Targets Chinese Speakers with Malware

Fake installers are the new frenemy! Netskope Threat Labs discovered a campaign where fake installers for software like Sogou and DeepSeek target Chinese speakers with malware. The Sainbox RAT and Hidden rootkit are the stars of this malicious show, potentially orchestrated by the Silver Fox group. Download with caution, folks!

Pro Dashboard

Hot Take:

Looks like Silver Fox is taking a page from the culinary world by serving up malware soufflés disguised as tasty software treats! These cyber chefs are whipping up some fake installers that are more deceptive than a magician’s rabbit. Beware of these digital delicacies, folks, because it’s not just your computer’s waistline that’s at risk—it’s your data! Let’s dive into the main course of this cyber caper.

Key Points:

  • Netskope Threat Labs has discovered a campaign using fake installers for popular software to target Chinese speakers with malware.
  • The malware includes the Sainbox RAT, a variant of Gh0stRAT, and an open-source Hidden rootkit.
  • The attack is attributed to the Silver Fox group with medium confidence.
  • Phishing websites deliver MSI files that disguise themselves as legitimate software installers.
  • These fake installers deploy malicious DLLs and shellcode to execute malware on the victim’s machine.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?