Silver Fox's Target Set Extends Well Beyond Chinese-Language Users
Silver Fox, a China-based intrusion set also tracked as Void Arachne, SwimSnake, The Great Thief of Valley, and UTG-Q-1000, has been active since at least 2022 [9][10]. The group first drew attention through financially motivated campaigns against Chinese-speaking users, but its target set has broadened considerably. By July 2026, researchers documented Silver Fox attacking a Japanese industrial manufacturing organization with a three-driver BYOVD chain delivering ValleyRAT [8]. Sekoia's TDR team reported campaigns spanning Japan, Malaysia, the Philippines, Thailand, Indonesia, Singapore, and India since at least late 2025 [9][10]. The group now straddles two operational profiles: opportunistic cybercrime campaigns using commodity malware like Blackmoon, and more targeted, APT-style operations that Sekoia assesses are "likely for intelligence collection" [10].
Sainbox RAT, a Gh0stRAT variant first identified by Proofpoint [6], remains one tool in this expanding arsenal. Netskope published research on June 26, 2025 documenting a campaign that used fake WPS Office, Sogou, and DeepSeek installer pages to deliver Sainbox RAT alongside the open-source Hidden rootkit [1]. That campaign targeted Chinese speakers specifically, but the broader Silver Fox operation now encompasses industrial targets in Japan, technology and IT organizations, and users of popular applications across South and Southeast Asia [8][9][10].
Background: From Sainbox RAT to a Full Gh0stRAT Derivative Ecosystem
Gh0stRAT's source code has been publicly available for years, spawning many forks [6]. Sainbox RAT is one such fork [6]. Proofpoint saw Sainbox disappear from its threat data for years before it reappeared across nearly 20 email campaigns starting in April 2023 [6][7]. Those campaigns were generally low-volume, sent to global organizations with operations in China, using Chinese-language invoice-themed lures that spoofed Chinese office and invoicing companies [6].
Proofpoint assessed the activity likely involved multiple distinct clusters rather than a single entity, based on variation in infrastructure, sender domains, and targeting [6]. Over 30 campaigns using malware associated with Chinese cybercrime activity were detected in 2023 alone: at least 20 delivering Sainbox, three delivering Purple Fox, and six delivering a then-new strain called ValleyRAT [7].
Silver Fox's tooling has continued to expand. AtlasCross RAT (also called AtlasAgent), documented in a March 2026 report, represents the current state of the group's development, building on Gh0st RAT protocol foundations consistent with the ValleyRAT and Winos 4.0 lineage [9]. The group's known arsenal now includes ValleyRAT (related to Winos 4.0), Gh0stCringe, HoldingHands RAT (also known as Gh0stBins), AtlasCross RAT, and Sainbox RAT [9][10]. Some researchers believe Silver Fox may be an APT masquerading as a cybercrime group [3].
Sainbox RAT Infection Chain: Fake Installers and DLL Side-Loading
The Sainbox RAT campaign documented by Netskope in June 2025 used phishing websites that mimicked official software portals for WPS Office, Sogou, and DeepSeek [1]. The phishing site wpsice[.]com was one confirmed distribution point [2]. When a victim clicked the download button, the file was fetched from a different URL than displayed on the page [1][3].
The installers were primarily MSI files, though a PE installer was also observed for the WPS Office variant [3][5]. Upon execution, the MSI runs a legitimate binary called Shine.exe, which side-loads a malicious DLL named libcef.dll, a counterfeit version of the Chromium Embedded Framework library [1][2][5]. The genuine software also installs during this process, reducing suspicion [3][4].
The malicious libcef.dll exports a function called cef_api_hash, which serves as the entry point [4][5]. This function establishes persistence by writing the Shine.exe path to the Windows Registry Run key under the name "Management" [4]. It then reads the contents of a dropped file called 1.txt into memory [1][5]. That file contains shellcode based on the open-source sRDI (Shellcode Reflective DLL Injection) tool, with its MZ header stripped to evade forensic analysis [1][4].
The shellcode performs reflective DLL loading, injecting a hidden DLL named Install.dll into memory without touching disk [4][5]. It invokes Install.dll's exported function Shellex to initiate malicious activity [1][5]. The resulting Sainbox RAT DLL carries a second PE binary embedded in its .data section: a rootkit driver derived from the open-source Hidden project [1][2][5].
Hidden Rootkit Deployment and Kernel-Level Stealth
The Sainbox RAT creates a Windows service named "Sainbox" for the rootkit and loads the driver using the NtLoadDriver function [1][5]. The rootkit's primary purpose is to conceal processes, files, and registry keys and values using a mini-filter and kernel callbacks [1][3]. It can also protect itself and specific processes from termination, and it exposes a user-accessible interface via IOCTL [3].
This rootkit deployment degrades endpoint detection by hiding the RAT's processes and preventing security tools from terminating them. The combination of a commodity RAT with a kernel-mode rootkit gives the operator persistent, stealthy access to compromised systems.
Expanded Targeting: From Chinese Speakers to Asia-Pacific Industrial and Technology Sectors
The original Sainbox RAT email campaigns from 2023 focused on Chinese-language speakers at global organizations with operations in China [6]. The June 2025 fake installer campaign maintained that focus [1]. But Silver Fox's broader targeting has expanded substantially.
In July 2026, Silver Fox targeted a Japanese industrial manufacturing organization with an invoice-themed phishing lure, using attacker-controlled content hosted on QQ and Tencent Cloud services to deliver ValleyRAT through a ZIP archive and a three-driver BYOVD framework [8]. The campaign reportedly used drivers BootRepair.sys and EnPortv.sys, which had not been previously reported in connection with the group, alongside the previously known wsftprm.sys [8].
Researchers documented eleven confirmed delivery domains impersonating brands including Surfshark VPN, Signal, Telegram, Zoom, Microsoft Teams, and others, with the majority registered on a single day (October 27, 2025) [9]. The target geography extended across Japan, Malaysia, the Philippines, Thailand, Indonesia, Singapore, and India [9]. This represents a deliberate expansion from Chinese-speaking populations into broader Asia-Pacific targeting.
Sekoia's research confirmed that Silver Fox operates dual-objective campaigns: financially motivated operations using commodity malware like Blackmoon alongside more sophisticated, espionage-oriented operations using ValleyRAT with kernel-mode rootkits [10]. The group has also deployed a Python-based stealer and abused the legitimate RMM tool SyncFuture TSM [9][10].
An April 2026 campaign used a malicious MSI named 点击安装中文语言包a.msi posing as a Telegram Chinese language pack, delivering ValleyRAT and a kernel-mode rootkit based on the wnBios driver [11]. The six-stage infection chain queried WMI for Chinese consumer antivirus processes (360 Safe's ZhuDongFangYu.exe, Tencent PC Manager's QQPCRTP.exe, and Huorong's HipsDaemon.exe) to select its evasion approach [11].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| domain | wpsice[.]com |
Phishing website distributing malicious MSI installers | [2] |
| domain | fakaka16.top |
Sainbox RAT C2 domain (port 3366) | [6] |
| domain | fakaka9.top |
C2 domain registered by Sainbox RAT actor | [6] |
| domain | kakafa.top |
Sainbox RAT C2 (port 3367) | [6] |
| domain | rus3rcqtp.hn-bkt.clouddn.com |
Hosted Sainbox RAT payload ZIP | [6] |
| domain | 51fapiaoyun.com |
Sainbox RAT payload delivery | [6] |
| domain | bifa668[.]com |
AtlasCross RAT second-stage shellcode C2 (TCP port 9899) | [9] |
| IP | 118.107.43.65 |
ValleyRAT C2 server (port 5040) | [11] |
q1045582630@qq.com |
Sainbox sender email, Aug 2023 campaign | [6] | |
| filename | Shine.exe |
Legitimate binary abused for DLL side-loading | [1][2][3] |
| filename | libcef.dll |
Malicious DLL side-loaded by Shine.exe | [1][2][5] |
| filename | Install.dll |
Sainbox RAT DLL, exported function Shellex |
[1][5] |
| filename | 1.txt |
Shellcode container, MZ header stripped | [1][4] |
| filename | 点击安装中文语言包a.msi |
Fake Telegram Chinese language pack MSI | [11] |
| malware | Sainbox RAT |
Gh0stRAT variant | [1][6] |
| malware | Hidden rootkit |
Open-source rootkit, loaded as service "Sainbox" | [1][5] |
Additional MD5 hashes from Netskope's published IOC repository [14]:
| Type | Value | Source |
|---|---|---|
| MD5 | F0893BBA522061E58299C295F5838DFC |
[14] |
| MD5 | BA6A4699F59E557537BCB6463B4BA75B |
[14] |
| MD5 | BB43584E3308237BD97FB2CD483898A0 |
[14] |
| MD5 | 8C6DF59659D4407FA4A07CC094F46DD5 |
[14] |
| MD5 | 6442971B32BAD1F3B30306B60544FAEA |
[14] |
| MD5 | 0056D6F321A87CAF26EE800933BA4BCF |
[14] |
| MD5 | 78F0F18CDDF3D9FF82D001A2B5EAA429 |
[14] |
| MD5 | C4582684928195F0EE6D2411BDF5DFAD |
[14] |
| MD5 | FE56BCA80C57480CD68C43C192FCA295 |
[14] |
| MD5 | C08B995F8A76F1059BA188DC862C98A2 |
[14] |
| IP | 45.207.12.71 |
[14] |
| IP | 154.23.221.136 |
[14] |
| IP | 206.119.124.126 |
[14] |
MITRE ATT&CK Techniques
| Technique ID | Name | Context |
|---|---|---|
| T1574.002 | Hijack Execution Flow: DLL Side-Loading | Shine.exe side-loads malicious libcef.dll [1][2][12] |
| T1014 | Rootkit | Hidden rootkit conceals processes, files, registry entries via mini-filter and kernel callbacks [1][3][13] |
| T1204.002 | User Execution: Malicious File | Victims download and execute fake MSI installers from phishing sites [1] |
| T1036.005 | Masquerading: Match Legitimate Name or Location | Malicious DLL named libcef.dll to match legitimate CEF library [1][5] |
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys | Persistence via Registry Run key under name "Management" [4] |
| T1055 | Process Injection | Reflective DLL injection via sRDI shellcode [1][4] |
| T1543.003 | Create or Modify System Process: Windows Service | RAT creates service named "Sainbox" to load rootkit driver [1][5] |
| T1204.001 | User Execution: Malicious Link | Victims visit fake software download websites and click download links [1][2] |
Detection and Hunting
Registry Persistence:
Search for new Run key entries with the value name "Management" pointing to executables in unusual directories. The Sainbox RAT campaign uses this specific key name [4].
title: Sainbox RAT Registry Persistence via Management Run Key
status: experimental
author: RedSheepSec
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|endswith: '\Software\Microsoft\Windows\CurrentVersion\Run\Management'
condition: selection
level: high
DLL Side-Loading Detection:
Monitor for Shine.exe loading libcef.dll from non-standard paths (outside legitimate CEF/Chromium installations). Legitimate CEF applications load libcef.dll from within their own program directories, typically under Program Files.
title: Shine.exe Loading Suspicious libcef.dll for Sainbox RAT Side-Loading
status: experimental
author: RedSheepSec
logsource:
product: windows
category: image_load
detection:
selection:
Image|endswith: '\Shine.exe'
ImageLoaded|endswith: '\libcef.dll'
filter:
ImageLoaded|startswith:
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
condition: selection and not filter
level: high
Service Creation:
Alert on creation of a Windows service named "Sainbox." This is the specific service name the RAT uses to load its rootkit driver via NtLoadDriver [1][5].
Network Indicators:
Monitor DNS queries for the C2 domains listed in the IOC table above, particularly fakaka16.top, fakaka9.top, kakafa.top, and bifa668[.]com [6][9]. Look for outbound connections on non-standard ports (3366, 3367, 5040, 9899).
File System Artifacts:
Hunt for the presence of 1.txt files in the same directory as Shine.exe and libcef.dll. The shellcode with a stripped MZ header in a text file is a distinctive forensic artifact [1][4].
BYOVD Driver Loading:
For organizations tracking Silver Fox's broader toolkit, monitor for loading of drivers named BootRepair.sys, EnPortv.sys, wsftprm.sys, or amsdk.sys, all of which the group has reportedly used in BYOVD attacks [8].
Analysis
Silver Fox's target set has evolved along two distinct axes. The first is geographic: from a near-exclusive focus on Chinese-speaking populations through 2024, the group has expanded operations across the Asia-Pacific region, with confirmed campaigns in Japan, Southeast Asia, and South Asia [8][9]. The second is sectoral: the Japanese manufacturing campaign reported in July 2026 marks confirmed targeting of the industrial sector, while the broader fake-domain infrastructure impersonating VPN, messaging, and conferencing tools suggests interest in technology-sector employees and general enterprise users [8][9].
The group's dual-objective posture complicates defender prioritization. Financially motivated campaigns using Blackmoon or commodity stealers may appear as routine cybercrime, while APT-style operations using ValleyRAT with kernel-mode rootkits represent a meaningfully different threat level [10]. Organizations that dismiss initial indicators as low-tier cybercrime risk missing the escalation to persistent access and potential intelligence collection.
The tooling evolution is also notable. Silver Fox has moved from relying primarily on Gh0stRAT forks to maintaining what amounts to a modular toolkit with Rust and Python loaders, BYOVD frameworks, RMM tool abuse, and multiple RAT families deployed based on operational requirements [8][9][10][11].
Red Sheep Assessment
Confidence: Moderate
The sources collectively point to Silver Fox likely operating as a dual-purpose group that uses financially motivated campaigns as either cover for or a complement to intelligence collection operations. Sekoia explicitly describes a pivot toward "APT-style operations" beginning in 2024 [10], and SecurityWeek notes that "some researchers believe it may be an APT masquerading as a cybercrime group" [3]. The geographic expansion into Japan's industrial manufacturing sector and the deployment of driver exploits for kernel access are not consistent with purely profit-motivated activity.
Sainbox RAT itself, as documented in the June 2025 campaign, represents a relatively straightforward component in a much larger operation. The more significant signal is the pace at which Silver Fox rotates lure themes to match trending software. The group exploited DeepSeek's popularity within months of its rise [1][4], registered domains impersonating Zoom, Teams, Signal, and Telegram in a single day [9], and adapted to Telegram language pack distribution by April 2026 [11]. This pattern suggests a dedicated infrastructure team that can rapidly stand up convincing phishing sites for whatever application is generating search traffic in their target regions.
An alternative interpretation is that these campaigns represent multiple loosely affiliated operators sharing infrastructure and tooling rather than a single coordinated group. Proofpoint's 2023 assessment that the Sainbox-related activity "likely stems from multiple distinct clusters" supports this possibility [6]. The attribution to Silver Fox carries medium confidence across all reporting, and defenders should treat the TTPs and IOCs as actionable regardless of whether a single group or a cluster is responsible.
Defender's Checklist
- ▢[ ] Block domains
wpsice[.]com,fakaka16.top,fakaka9.top,kakafa.top,bifa668[.]com, and IPs45.207.12.71,154.23.221.136,206.119.124.126,118.107.43.65at your DNS resolver and perimeter firewall [6][9][11][14] - ▢[ ] Hunt for Registry Run key entries named "Management" across all endpoints using your EDR's registry query capability or the Sigma rule above [4]
- ▢[ ] Search for
Shine.exeloadinglibcef.dlloutside legitimate Chromium/CEF installation paths; query example for CrowdStrike:event_simpleName=DllLoad FileName="libcef.dll" AND ContextBaseFileName="Shine.exe"[1][2] - ▢[ ] Audit kernel driver loads for Silver Fox BYOVD indicators:
BootRepair.sys,EnPortv.sys,wsftprm.sys,amsdk.sys; check Windows System event log EventID 7045 for service installations of unfamiliar drivers [8] - ▢[ ] Brief users who access Chinese-language software portals (WPS Office, Sogou, DeepSeek, Telegram language packs) about the fake installer threat, and consider restricting MSI execution from user-writable directories via AppLocker or WDAC policies [1][11]
References
[1] https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
[2] https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html
[3] https://www.securityweek.com/chinese-hackers-target-chinese-users-with-rat-rootkit/
[4] https://cybersecuritynews.com/weaponized-deepseek-installers-delivers-sainbox-rat/
[5] https://gbhackers.com/threat-actors-impersonate-wps-office-and-deepseek/
[6] https://www.proofpoint.com/us/blog/threat-insight/chinese-malware-appears-earnest-across-cybercrime-threat-landscape
[7] https://thehackernews.com/2023/09/sophisticated-phishing-campaign_20.html
[8] https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
[9] https://thehackernews.com/2026/03/silver-fox-expands-asia-cyber-campaign.html
[10] https://www.sekoia.com/blog/silver-fox-the-only-tax-audit-where-the-fine-print-installs-malware
[11] https://gbhackers.com/silver-fox-campaign/
[12] https://attack.mitre.org/versions/v12/techniques/T1574/002/
[13] https://attack.mitre.org/techniques/T1014/
[14] https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Malware/Sainbox/IOCs
Event Timeline
Timeline
Entity Relationships
Entity Graph (10 entities, 5 relationships)
Diamond Model
Diamond Model
Hunt Guide: Silver Fox (Void Arachne) - Sainbox RAT, ValleyRAT, and Gh0stRAT Derivative Arsenal
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Silver Fox intrusion set activity is present in our environment, we expect to observe DLL side-loading of libcef.dll by Shine.exe, Registry Run key persistence under the name 'Management', Windows service creation named 'Sainbox', DNS queries to known C2 domains (fakaka16.top, kakafa.top, bifa668.com), and kernel driver loading for rootkit deployment, visible in Sysmon image load events, registry modification logs, service installation events, DNS query logs, and driver load telemetry.
Intelligence Summary: Silver Fox is a China-based intrusion set, also tracked as Void Arachne and UTG-Q-1000, that has expanded from financially motivated campaigns against Chinese-speaking users to broader Asia-Pacific targeting including industrial manufacturing in Japan and technology sectors across Southeast Asia. The group deploys a growing arsenal of Gh0stRAT derivatives including Sainbox RAT, ValleyRAT, AtlasCross RAT, and HoldingHands RAT, frequently combining them with kernel-mode rootkits derived from the open-source Hidden project and BYOVD driver exploitation chains. Some researchers assess Silver Fox may be an APT masquerading as a cybercrime group, conducting dual-objective campaigns that blend commodity malware operations with espionage-oriented intrusions likely for intelligence collection.
Confidence: Moderate | Priority: High
Scope
- Networks: All enterprise Windows endpoints, with priority on systems used by personnel with access to Chinese-language software, industrial control systems, and Asia-Pacific focused operations. Include DMZ systems and any endpoints with internet-facing services that could serve as initial access vectors.
- Timeframe: 90 days retrospective, with continuous forward monitoring. The Netskope campaign was documented in June 2025, Silver Fox domain registrations occurred in October 2025, and the most recent campaigns extend through July 2026. Hunt should cover at minimum January 2025 through present.
- Priority Systems: Endpoints used by personnel who may download Chinese-language software (WPS Office, Sogou, DeepSeek), systems in industrial manufacturing or technology sectors, any systems with connections to Asia-Pacific operations, systems showing recent MSI installations from user-writable directories, and domain controllers or high-value servers where rootkit deployment would be most impactful.
MITRE ATT&CK Techniques
T1574.002: Hijack Execution Flow: DLL Side-Loading (Persistence, Privilege Escalation, Defense Evasion) [P1]
Silver Fox uses a legitimate binary called Shine.exe to side-load a malicious DLL named libcef.dll, which masquerades as the Chromium Embedded Framework library. The malicious DLL exports a function called cef_api_hash that initiates the infection chain, including persistence establishment and shellcode execution.
Splunk SPL:
index=sysmon EventCode=7 ImageLoaded="*\\libcef.dll" Image="*\\Shine.exe" NOT ImageLoaded="C:\\Program Files*" NOT ImageLoaded="C:\\Program Files (x86)*"
| stats count by Computer, Image, ImageLoaded, Hashes
| table Computer, Image, ImageLoaded, Hashes, count
Elastic KQL:
event.code:"7" AND process.executable:*\\Shine.exe AND dll.path:*\\libcef.dll AND NOT dll.path:("C:\\Program Files\\*" OR "C:\\Program Files (x86)\\*")
Sigma Rule:
title: Shine.exe Loading Suspicious libcef.dll for Sainbox RAT Side-Loading
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects Shine.exe loading libcef.dll from non-standard paths, indicative of Sainbox RAT DLL side-loading as documented by Netskope.
references:
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
- https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html
logsource:
product: windows
category: image_load
detection:
selection:
Image|endswith: '\Shine.exe'
ImageLoaded|endswith: '\libcef.dll'
filter:
ImageLoaded|startswith:
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
condition: selection and not filter
falsepositives:
- Legitimate applications using Shine.exe with CEF libraries in standard paths
level: high
tags:
- attack.persistence
- attack.defense_evasion
- attack.t1574.002
Tune by excluding any legitimate software installations that use both Shine.exe and libcef.dll. The combination of these two specific filenames outside Program Files directories is highly suspicious. Also hunt for Shine.exe in user-writable directories such as %TEMP%, %APPDATA%, or Downloads.
T1547.001: Boot or Logon Autostart Execution: Registry Run Keys (Persistence) [P1]
The malicious libcef.dll establishes persistence by writing the Shine.exe path to the Windows Registry Run key under the value name 'Management'. This ensures the side-loading chain executes on every user logon.
Splunk SPL:
index=sysmon EventCode=13 TargetObject="*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Management"
| stats count by Computer, Image, TargetObject, Details
| table Computer, Image, TargetObject, Details, count
Elastic KQL:
event.code:"13" AND registry.path:*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Management
Sigma Rule:
title: Sainbox RAT Registry Persistence via Management Run Key
id: b2c3d4e5-f6a7-8901-bcde-f12345678901
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects creation of a Registry Run key entry named Management, used by Sainbox RAT for persistence.
references:
- https://cybersecuritynews.com/weaponized-deepseek-installers-delivers-sainbox-rat/
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|endswith: '\Software\Microsoft\Windows\CurrentVersion\Run\Management'
condition: selection
falsepositives:
- Legitimate management software using the exact value name Management in Run keys
level: high
tags:
- attack.persistence
- attack.t1547.001
The value name 'Management' is generic enough to potentially appear in legitimate software. Validate by checking the path in the Details/registry value data: if it points to Shine.exe or an executable in a user-writable directory, escalate immediately.
T1543.003: Create or Modify System Process: Windows Service (Persistence, Privilege Escalation) [P1]
Sainbox RAT creates a Windows service named 'Sainbox' to load its Hidden rootkit driver using the NtLoadDriver function. This provides kernel-level persistence and enables rootkit capabilities for process, file, and registry concealment.
Splunk SPL:
index=winevent EventCode=7045 ServiceName="Sainbox"
| stats count by Computer, ServiceName, ImagePath, ServiceType, AccountName
| table Computer, ServiceName, ImagePath, ServiceType, AccountName, count
Elastic KQL:
event.code:"7045" AND winlog.event_data.ServiceName:"Sainbox"
Sigma Rule:
title: Sainbox RAT Rootkit Service Installation
id: c3d4e5f6-a7b8-9012-cdef-123456789012
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects creation of a Windows service named Sainbox, used to load the Hidden rootkit driver as part of the Sainbox RAT infection chain.
references:
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
- https://gbhackers.com/threat-actors-impersonate-wps-office-and-deepseek/
logsource:
product: windows
service: system
detection:
selection:
EventID: 7045
ServiceName: 'Sainbox'
condition: selection
falsepositives:
- None expected. The service name Sainbox is specific to this malware.
level: critical
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1543.003
A service named 'Sainbox' is a strong indicator of compromise with near-zero false positive rate. Any hit should be treated as a confirmed infection requiring immediate incident response.
T1014: Rootkit (Defense Evasion) [P1]
Silver Fox deploys a kernel-mode rootkit derived from the open-source Hidden project. The rootkit conceals processes, files, and registry keys using mini-filter drivers and kernel callbacks. It also protects itself and specific processes from termination and exposes a user-accessible interface via IOCTL. Silver Fox has also used BYOVD techniques with drivers BootRepair.sys, EnPortv.sys, wsftprm.sys, and amsdk.sys.
Splunk SPL:
index=sysmon EventCode=6 ImageLoaded IN ("*\\BootRepair.sys", "*\\EnPortv.sys", "*\\wsftprm.sys", "*\\amsdk.sys")
| stats count by Computer, ImageLoaded, Hashes, Signed, SignatureStatus
| table Computer, ImageLoaded, Hashes, Signed, SignatureStatus, count
Elastic KQL:
event.code:"6" AND file.path:(*\\BootRepair.sys OR *\\EnPortv.sys OR *\\wsftprm.sys OR *\\amsdk.sys)
Sigma Rule:
title: Silver Fox BYOVD Driver Loading
id: d4e5f6a7-b8c9-0123-defa-234567890123
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects loading of known Silver Fox BYOVD drivers used to achieve kernel-level access for rootkit deployment.
references:
- https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
logsource:
product: windows
category: driver_load
detection:
selection:
ImageLoaded|endswith:
- '\BootRepair.sys'
- '\EnPortv.sys'
- '\wsftprm.sys'
- '\amsdk.sys'
condition: selection
falsepositives:
- Legitimate use of BootRepair.sys in Windows recovery scenarios
level: critical
tags:
- attack.defense_evasion
- attack.t1014
EnPortv.sys and BootRepair.sys were newly reported in connection with Silver Fox in July 2026. Cross-reference any hits with known vulnerable driver lists. Also consider broader BYOVD hunting by looking for unsigned or revoked-signature drivers loaded from user-writable directories.
T1204.002: User Execution: Malicious File (Execution) [P2]
Silver Fox distributes malicious MSI and PE installers that masquerade as legitimate software (WPS Office, Sogou, DeepSeek, Telegram language packs). Victims download and execute these files from phishing websites, initiating the infection chain. The genuine software also installs during this process, reducing suspicion.
Splunk SPL:
index=sysmon EventCode=1 (Image="*\\msiexec.exe" OR OriginalFileName="msiexec.exe") CommandLine="*\.msi*"
| search CommandLine IN ("*wps*", "*sogou*", "*deepseek*", "*语言包*", "*telegram*", "*surfshark*", "*signal*", "*zoom*", "*teams*")
| stats count by Computer, User, ParentImage, CommandLine
| table Computer, User, ParentImage, CommandLine, count
Elastic KQL:
event.code:"1" AND process.name:"msiexec.exe" AND process.command_line:(*wps* OR *sogou* OR *deepseek* OR *telegram* OR *surfshark* OR *signal*)
Sigma Rule:
title: Suspicious MSI Execution Matching Silver Fox Lure Themes
id: e5f6a7b8-c9d0-1234-efab-345678901234
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects MSI installations with filenames matching known Silver Fox lure themes including fake software installers.
references:
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
- https://gbhackers.com/silver-fox-campaign/
logsource:
product: windows
category: process_creation
detection:
selection_msi:
Image|endswith: '\msiexec.exe'
selection_lure:
CommandLine|contains:
- '\u70b9\u51fb\u5b89\u88c5\u4e2d\u6587\u8bed\u8a00\u5305'
- 'deepseek'
- 'wpsice'
condition: selection_msi and selection_lure
falsepositives:
- Legitimate DeepSeek or WPS Office installations from official sources
level: high
tags:
- attack.execution
- attack.t1204.002
This rule targets known lure themes. Broader hunting should include any MSI execution from user-writable directories (Downloads, Temp, Desktop). Consider AppLocker or WDAC policies to restrict MSI execution from these paths.
T1036.005: Masquerading: Match Legitimate Name or Location (Defense Evasion) [P2]
The malicious DLL is named libcef.dll to match the legitimate Chromium Embedded Framework library. The exported function cef_api_hash also mimics legitimate CEF exports to avoid suspicion during static analysis.
Splunk SPL:
index=sysmon EventCode=7 ImageLoaded="*\\libcef.dll" NOT ImageLoaded="C:\\Program Files*" NOT ImageLoaded="C:\\Program Files (x86)*" NOT Image="*\\chrome.exe" NOT Image="*\\msedge.exe" NOT Image="*\\brave.exe"
| stats count by Computer, Image, ImageLoaded, Hashes
| table Computer, Image, ImageLoaded, Hashes, count
Elastic KQL:
event.code:"7" AND dll.name:"libcef.dll" AND NOT dll.path:("C:\\Program Files\\*" OR "C:\\Program Files (x86)\\*") AND NOT process.name:(chrome.exe OR msedge.exe OR brave.exe)
Sigma Rule:
title: Suspicious libcef.dll Load Outside Standard Chromium Paths
id: f6a7b8c9-d0e1-2345-fabc-456789012345
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects loading of libcef.dll from non-standard locations, which may indicate DLL side-loading by malware masquerading as the Chromium Embedded Framework.
references:
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
logsource:
product: windows
category: image_load
detection:
selection:
ImageLoaded|endswith: '\libcef.dll'
filter_legitimate_paths:
ImageLoaded|startswith:
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
condition: selection and not filter_legitimate_paths and not filter_browsers
falsepositives:
- Portable Chromium-based applications or Electron apps running from non-standard paths
level: medium
tags:
- attack.defense_evasion
- attack.t1036.005
Some Electron-based applications may legitimately load libcef.dll from non-standard paths. Tune by whitelisting known legitimate Electron apps in your environment. Focus investigation on instances where the loading process is Shine.exe.
T1055: Process Injection (Defense Evasion, Privilege Escalation) [P1]
The Sainbox RAT infection chain uses shellcode based on the open-source sRDI (Shellcode Reflective DLL Injection) tool to reflectively load Install.dll into memory without writing it to disk. The shellcode is stored in a file called 1.txt with its MZ header stripped to evade forensic analysis.
Splunk SPL:
index=sysmon (EventCode=8 OR EventCode=10) SourceImage="*\\Shine.exe"
| stats count by Computer, EventCode, SourceImage, TargetImage, CallTrace
| table Computer, EventCode, SourceImage, TargetImage, CallTrace, count
Elastic KQL:
(event.code:"8" OR event.code:"10") AND process.executable:*\\Shine.exe
Sigma Rule:
title: Shine.exe Performing Process Injection via sRDI
id: a7b8c9d0-e1f2-3456-abcd-567890123456
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects Shine.exe performing cross-process injection, which may indicate Sainbox RAT reflective DLL injection via sRDI shellcode.
references:
- https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery
logsource:
product: windows
category: create_remote_thread
detection:
selection:
SourceImage|endswith: '\Shine.exe'
condition: selection
falsepositives:
- Unknown legitimate uses of Shine.exe creating remote threads
level: critical
tags:
- attack.defense_evasion
- attack.privilege_escalation
- attack.t1055
Shine.exe creating remote threads is highly anomalous and should be investigated immediately. Also hunt for the file 1.txt co-located with Shine.exe and libcef.dll, as this is a distinctive forensic artifact of the Sainbox RAT infection chain.
T1204.001: User Execution: Malicious Link (Execution) [P1]
Victims visit fake software download websites impersonating WPS Office, Sogou, DeepSeek, Surfshark VPN, Signal, Telegram, Zoom, and Microsoft Teams. The phishing site wpsice.com was one confirmed distribution point. Eleven confirmed delivery domains were registered, with the majority on a single day (October 27, 2025).
Splunk SPL:
index=corelight sourcetype=corelight_dns query IN ("wpsice.com", "fakaka16.top", "fakaka9.top", "kakafa.top", "bifa668.com", "51fapiaoyun.com")
| stats count by src, query, answers
| table src, query, answers, count
Elastic KQL:
dns.question.name:(wpsice.com OR fakaka16.top OR fakaka9.top OR kakafa.top OR bifa668.com OR 51fapiaoyun.com)
Sigma Rule:
title: DNS Query to Silver Fox C2 or Phishing Domains
id: b8c9d0e1-f2a3-4567-bcde-678901234567
status: experimental
author: RedSheepSec
date: 2025/07/16
description: Detects DNS queries to known Silver Fox phishing and C2 domains associated with Sainbox RAT and ValleyRAT campaigns.
references:
- https://www.proofpoint.com/us/blog/threat-insight/chinese-malware-appears-earnest-across-cybercrime-threat-landscape
- https://thehackernews.com/2025/06/chinese-group-silver-fox-uses-fake.html
logsource:
product: dns
detection:
selection:
query|endswith:
- 'wpsice.com'
- 'fakaka16.top'
- 'fakaka9.top'
- 'kakafa.top'
- 'bifa668.com'
- '51fapiaoyun.com'
- 'rus3rcqtp.hn-bkt.clouddn.com'
condition: selection
falsepositives:
- None expected
level: critical
tags:
- attack.execution
- attack.t1204.001
Any DNS resolution of these domains should trigger immediate investigation. These domains are confirmed C2 and phishing infrastructure for Silver Fox campaigns.
Indicators of Compromise
| Type | Value | Context | |
|---|---|---|---|
| domain | wpsice.com |
Phishing website distributing malicious MSI installers masquerading as WPS Office \ | VirusTotal 11/89 malicious |
| domain | fakaka16.top |
Sainbox RAT C2 domain communicating on port 3366 \ | VirusTotal 13/89 malicious |
| domain | fakaka9.top |
C2 domain registered by Sainbox RAT actor \ | VirusTotal 8/89 malicious |
| domain | kakafa.top |
Sainbox RAT C2 domain communicating on port 3367 \ | VirusTotal 14/89 malicious |
| domain | rus3rcqtp.hn-bkt.clouddn.com |
Chinese CDN domain hosting Sainbox RAT payload ZIP file \ | VirusTotal 1/89 malicious |
| domain | 51fapiaoyun.com |
Sainbox RAT payload delivery domain \ | VirusTotal 12/89 malicious |
| domain | bifa668.com |
AtlasCross RAT second-stage shellcode C2 domain communicating on TCP port 9899 \ | VirusTotal 20/89 malicious |
| ip | 118.107.43.65 |
ValleyRAT C2 server communicating on port 5040, hosted by CTG Server Ltd in Hong Kong \ | AbuseIPDB confidence 0% (0 reports, HK) |
| ip | 45.207.12.71 |
Sainbox RAT infrastructure IP from Netskope IOC repository \ | AbuseIPDB confidence 0% (0 reports, HK) |
| ip | 154.23.221.136 |
Sainbox RAT infrastructure IP from Netskope IOC repository \ | AbuseIPDB confidence 0% (0 reports, HK) |
| ip | 206.119.124.126 |
Sainbox RAT infrastructure IP from Netskope IOC repository \ | AbuseIPDB confidence 0% (0 reports, HK) |
| hash_md5 | f0893bba522061e58299c295f5838dfc |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 28/75 malicious \ | VirusTotal 28/75 malicious (trojan.shellcode/marte) |
| hash_md5 | ba6a4699f59e557537bcb6463b4ba75b |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 28/73 malicious \ | VirusTotal 28/73 malicious (trojan.farfli/marte) |
| hash_md5 | bb43584e3308237bd97fb2cd483898a0 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 30/76 malicious \ | VirusTotal 30/76 malicious (trojan.marte/farfli) |
| hash_md5 | 8c6df59659d4407fa4a07cc094f46dd5 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 34/72 malicious \ | VirusTotal 34/72 malicious (trojan.farfli/agentb) |
| hash_md5 | 6442971b32bad1f3b30306b60544faea |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 29/75 malicious \ | VirusTotal 29/75 malicious (trojan.marte/shellcode) |
| hash_md5 | 0056d6f321a87caf26ee800933ba4bcf |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 36/75 malicious \ | VirusTotal 36/75 malicious (trojan.farfli/sainbox) |
| hash_md5 | 78f0f18cddf3d9ff82d001a2b5eaa429 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 30/76 malicious \ | VirusTotal 30/76 malicious (trojan.marte/shellcode) |
| hash_md5 | c4582684928195f0ee6d2411bdf5dfad |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 29/75 malicious \ | VirusTotal 29/75 malicious (trojan.farfli/dllhijack) |
| hash_md5 | fe56bca80c57480cd68c43c192fca295 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 53/75 malicious \ | VirusTotal 53/75 malicious (trojan.shellcoderunner/loader) |
| hash_md5 | c08b995f8a76f1059ba188dc862c98a2 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 48/75 malicious \ | VirusTotal 48/75 malicious (trojan.shellcoderunner/sainbox) |
| hash_md5 | 1b1ebdb45ed02695370227e7c897910e |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 52/76 malicious \ | VirusTotal 52/76 malicious (trojan.shellcoderunner/loader) |
| hash_md5 | 966310f10069f8443fe4d8adf4a7bd80 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 51/75 malicious \ | VirusTotal 51/75 malicious (trojan.shellcoderunner/dllhijack) |
| hash_md5 | 487fb061ed51046206e69b9c8f41e935 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 51/76 malicious \ | VirusTotal 51/76 malicious (trojan.shellcoderunner/loader) |
| hash_md5 | e59062d8ab72d71a9b9ba8b4152e730d |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 52/75 malicious \ | VirusTotal 52/75 malicious (trojan.shellcoderunner/dllhijack) |
| hash_md5 | ab9ab337c4f4284b1176fa65817df5fe |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 33/75 malicious \ | VirusTotal 33/75 malicious (trojan.shellcode/marte) |
| hash_md5 | a04c9630adf4eadf3ac896bff8d9ead8 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 33/75 malicious \ | VirusTotal 33/75 malicious (trojan.shellcode/marte) |
| hash_md5 | c12f28d8a2e5726c8125c5738d97d478 |
Sainbox RAT sample hash from Netskope IOC repository, VirusTotal 28/75 malicious \ | VirusTotal 28/75 malicious (trojan.farfli/shellcode) |
q1045582630@qq.com |
Sainbox sender email used in August 2023 campaign | ||
| filename | Shine.exe |
Legitimate binary abused for DLL side-loading in Sainbox RAT infection chain | |
| filename | libcef.dll |
Malicious DLL side-loaded by Shine.exe masquerading as Chromium Embedded Framework library | |
| filename | Install.dll |
Sainbox RAT DLL payload with exported function Shellex, loaded via reflective DLL injection | |
| filename | 1.txt |
Shellcode container file with stripped MZ header, co-located with Shine.exe and libcef.dll | |
| url | http://rus3rcqtp.hn-bkt.clouddn.com/26866498.zip |
Proofpoint IOC, Chinese CDN payload download URL for Sainbox RAT | |
| url | http://51fapiaoyun.com/%E5%8F%91-%E7%A5%A8.rar |
ValleyRAT payload URL from Proofpoint IOC table | |
| url | http://124.220.35.63/laoxiang.exe |
ValleyRAT payload URL from Proofpoint IOC table | |
| url | https://drfs.ctcontents.com/file/40788929/860577489/ |
ValleyRAT payload URL from Proofpoint IOC table | |
| url | http://ckj2.cn/R8F |
ValleyRAT payload URL from Proofpoint IOC table | |
| url | https://zc1800.oss-cn-shenzhen.aliyuncs.com/piao |
ValleyRAT executable hosting URL from Proofpoint IOC table | |
| url | https://fhyhdf.oss-cn-hangzhou.aliyuncs.com/%E7%99%BC%E7%A5%A8.zip |
ValleyRAT payload URL from Proofpoint IOC table |
IOC Sweep Queries (Splunk):
index=corelight sourcetype=corelight_dns query="wpsice.com" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="fakaka16.top" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="fakaka9.top" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="kakafa.top" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="rus3rcqtp.hn-bkt.clouddn.com" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="51fapiaoyun.com" | stats count by src, query, answers | table src, query, answers, count
index=corelight sourcetype=corelight_dns query="bifa668.com" | stats count by src, query, answers | table src, query, answers, count
(index=corelight sourcetype=corelight_conn id.resp_h="118.107.43.65") OR (index=firewall-pan sourcetype="pan:traffic:aggregated" dest_ip="118.107.43.65") | stats count by src, dest, dest_port | table src, dest, dest_port, count
(index=corelight sourcetype=corelight_conn id.resp_h="45.207.12.71") OR (index=firewall-pan sourcetype="pan:traffic:aggregated" dest_ip="45.207.12.71") | stats count by src, dest, dest_port | table src, dest, dest_port, count
(index=corelight sourcetype=corelight_conn id.resp_h="154.23.221.136") OR (index=firewall-pan sourcetype="pan:traffic:aggregated" dest_ip="154.23.221.136") | stats count by src, dest, dest_port | table src, dest, dest_port, count
(index=corelight sourcetype=corelight_conn id.resp_h="206.119.124.126") OR (index=firewall-pan sourcetype="pan:traffic:aggregated" dest_ip="206.119.124.126") | stats count by src, dest, dest_port | table src, dest, dest_port, count
index=sysmon (Hashes="*F0893BBA522061E58299C295F5838DFC*" OR MD5="F0893BBA522061E58299C295F5838DFC") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*BA6A4699F59E557537BCB6463B4BA75B*" OR MD5="BA6A4699F59E557537BCB6463B4BA75B") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*BB43584E3308237BD97FB2CD483898A0*" OR MD5="BB43584E3308237BD97FB2CD483898A0") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*8C6DF59659D4407FA4A07CC094F46DD5*" OR MD5="8C6DF59659D4407FA4A07CC094F46DD5") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*6442971B32BAD1F3B30306B60544FAEA*" OR MD5="6442971B32BAD1F3B30306B60544FAEA") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*0056D6F321A87CAF26EE800933BA4BCF*" OR MD5="0056D6F321A87CAF26EE800933BA4BCF") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*78F0F18CDDF3D9FF82D001A2B5EAA429*" OR MD5="78F0F18CDDF3D9FF82D001A2B5EAA429") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*C4582684928195F0EE6D2411BDF5DFAD*" OR MD5="C4582684928195F0EE6D2411BDF5DFAD") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*FE56BCA80C57480CD68C43C192FCA295*" OR MD5="FE56BCA80C57480CD68C43C192FCA295") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*C08B995F8A76F1059BA188DC862C98A2*" OR MD5="C08B995F8A76F1059BA188DC862C98A2") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*1B1EBDB45ED02695370227E7C897910E*" OR MD5="1B1EBDB45ED02695370227E7C897910E") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*966310F10069F8443FE4D8ADF4A7BD80*" OR MD5="966310F10069F8443FE4D8ADF4A7BD80") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*487FB061ED51046206E69B9C8F41E935*" OR MD5="487FB061ED51046206E69B9C8F41E935") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*E59062D8AB72D71A9B9BA8B4152E730D*" OR MD5="E59062D8AB72D71A9B9BA8B4152E730D") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*AB9AB337C4F4284B1176FA65817DF5FE*" OR MD5="AB9AB337C4F4284B1176FA65817DF5FE") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*A04C9630ADF4EADF3AC896BFF8D9EAD8*" OR MD5="A04C9630ADF4EADF3AC896BFF8D9EAD8") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=sysmon (Hashes="*C12F28D8A2E5726C8125C5738D97D478*" OR MD5="C12F28D8A2E5726C8125C5738D97D478") | stats count by Computer, Image, Hashes | table Computer, Image, Hashes, count
index=corelight sourcetype=corelight_smtp mailfrom="*q1045582630@qq.com*" OR rcptto="*q1045582630@qq.com*" | stats count by src, dest, mailfrom, rcptto | table src, dest, mailfrom, rcptto, count
index=sysmon EventCode=1 Image="*\\Shine.exe" NOT Image="C:\\Program Files*"
| stats count by Computer, Image, ParentImage, CommandLine, Hashes
| table Computer, Image, ParentImage, CommandLine, Hashes, count
index=sysmon EventCode=7 ImageLoaded="*\\libcef.dll" NOT ImageLoaded="C:\\Program Files*" NOT ImageLoaded="C:\\Program Files (x86)*"
| stats count by Computer, Image, ImageLoaded, Hashes
| table Computer, Image, ImageLoaded, Hashes, count
index=sysmon EventCode=7 ImageLoaded="*\\Install.dll"
| stats count by Computer, Image, ImageLoaded, Hashes
| table Computer, Image, ImageLoaded, Hashes, count
index=sysmon EventCode=11 TargetFilename="*\\1.txt"
| stats count by Computer, Image, TargetFilename
| table Computer, Image, TargetFilename, count
index=corelight sourcetype=corelight_http host="rus3rcqtp.hn-bkt.clouddn.com" uri="*26866498.zip*" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="51fapiaoyun.com" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="124.220.35.63" uri="*laoxiang.exe*" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="drfs.ctcontents.com" uri="*40788929*" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="ckj2.cn" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="zc1800.oss-cn-shenzhen.aliyuncs.com" | stats count by src, host, uri | table src, host, uri, count
index=corelight sourcetype=corelight_http host="fhyhdf.oss-cn-hangzhou.aliyuncs.com" | stats count by src, host, uri | table src, host, uri, count
YARA Rules
SainboxRAT_SideLoadArtifacts: Detects Sainbox RAT infection chain artifacts including the malicious libcef.dll with cef_api_hash export, the shellcode container 1.txt pattern, and the Install.dll with Shellex export
rule SainboxRAT_SideLoadArtifacts {
meta:
author = "RedSheepSec"
description = "Detects Sainbox RAT DLL side-loading artifacts including malicious libcef.dll and Install.dll"
reference = "https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery"
date = "2025-07-16"
threat_actor = "Silver Fox"
strings:
$export1 = "cef_api_hash" ascii
$export2 = "Shellex" ascii
$dll_name1 = "Install.dll" ascii wide
$dll_name2 = "libcef.dll" ascii wide
$service_name = "Sainbox" ascii wide
$reg_key = "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Management" ascii wide
$sRDI_marker1 = { 4D 5A 90 00 03 00 00 00 }
$shine = "Shine.exe" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 5MB and
(($export1 and $export2) or
($service_name and $reg_key) or
($export1 and ($dll_name1 or $dll_name2)) or
(3 of ($export1, $export2, $service_name, $reg_key, $shine)))
}
SainboxRAT_MD5_Hashes: Detects known Sainbox RAT samples by matching MD5 hash byte patterns from Netskope IOC repository
rule SainboxRAT_MD5_Hashes {
meta:
author = "RedSheepSec"
description = "Detects known Sainbox RAT samples via embedded hash patterns from Netskope IOC repository"
reference = "https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Malware/Sainbox/IOCs"
date = "2025-07-16"
strings:
$s1 = "Sainbox" ascii wide nocase
$s2 = "cef_api_hash" ascii
$s3 = "Shellex" ascii
$s4 = "NtLoadDriver" ascii
$s5 = "Install.dll" ascii wide
$reg = "CurrentVersion\\Run\\Management" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 10MB and
(3 of them)
}
HiddenRootkit_DriverIndicators: Detects the Hidden open-source rootkit driver commonly deployed alongside Sainbox RAT, as well as known BYOVD drivers used by Silver Fox
rule HiddenRootkit_DriverIndicators {
meta:
author = "RedSheepSec"
description = "Detects Hidden rootkit driver and Silver Fox BYOVD driver indicators"
reference = "https://www.netskope.com/blog/deepseek-deception-sainbox-rat-hidden-rootkit-delivery"
date = "2025-07-16"
strings:
$driver1 = "BootRepair.sys" ascii wide nocase
$driver2 = "EnPortv.sys" ascii wide nocase
$driver3 = "wsftprm.sys" ascii wide nocase
$driver4 = "amsdk.sys" ascii wide nocase
$hidden1 = "HiddenDriver" ascii wide
$hidden2 = "HiddenService" ascii wide
$ioctl = "\\Device\\Hidden" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 2MB and
(any of ($driver*) or 2 of ($hidden*, $ioctl))
}
Suricata Rules
SID 2025071601: Detects DNS query for Sainbox RAT C2 domain fakaka16.top
alert dns $HOME_NET any -> any any (msg:"SILVERFOX Sainbox RAT C2 DNS Lookup - fakaka16.top"; dns.query; content:"fakaka16.top"; nocase; classtype:trojan-activity; sid:2025071601; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071602: Detects DNS query for Sainbox RAT C2 domain fakaka9.top
alert dns $HOME_NET any -> any any (msg:"SILVERFOX Sainbox RAT C2 DNS Lookup - fakaka9.top"; dns.query; content:"fakaka9.top"; nocase; classtype:trojan-activity; sid:2025071602; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071603: Detects DNS query for Sainbox RAT C2 domain kakafa.top
alert dns $HOME_NET any -> any any (msg:"SILVERFOX Sainbox RAT C2 DNS Lookup - kakafa.top"; dns.query; content:"kakafa.top"; nocase; classtype:trojan-activity; sid:2025071603; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071604: Detects DNS query for Silver Fox phishing domain wpsice.com
alert dns $HOME_NET any -> any any (msg:"SILVERFOX Phishing Domain DNS Lookup - wpsice.com"; dns.query; content:"wpsice.com"; nocase; classtype:trojan-activity; sid:2025071604; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071605: Detects DNS query for AtlasCross RAT C2 domain bifa668.com
alert dns $HOME_NET any -> any any (msg:"SILVERFOX AtlasCross RAT C2 DNS Lookup - bifa668.com"; dns.query; content:"bifa668.com"; nocase; classtype:trojan-activity; sid:2025071605; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071606: Detects outbound connection to ValleyRAT C2 IP 118.107.43.65 on port 5040
alert tcp $HOME_NET any -> 118.107.43.65 5040 (msg:"SILVERFOX ValleyRAT C2 Connection - 118.107.43.65:5040"; flow:to_server,established; classtype:trojan-activity; sid:2025071606; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071607: Detects outbound connection to Sainbox RAT infrastructure IP 45.207.12.71
alert ip $HOME_NET any -> 45.207.12.71 any (msg:"SILVERFOX Sainbox RAT Infrastructure - 45.207.12.71"; classtype:trojan-activity; sid:2025071607; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071608: Detects outbound connection to Sainbox RAT infrastructure IP 154.23.221.136
alert ip $HOME_NET any -> 154.23.221.136 any (msg:"SILVERFOX Sainbox RAT Infrastructure - 154.23.221.136"; classtype:trojan-activity; sid:2025071608; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071609: Detects outbound connection to Sainbox RAT infrastructure IP 206.119.124.126
alert ip $HOME_NET any -> 206.119.124.126 any (msg:"SILVERFOX Sainbox RAT Infrastructure - 206.119.124.126"; classtype:trojan-activity; sid:2025071609; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071610: Detects outbound TCP connection on Sainbox RAT non-standard C2 port 3366
alert tcp $HOME_NET any -> $EXTERNAL_NET 3366 (msg:"SILVERFOX Possible Sainbox RAT C2 on Port 3366"; flow:to_server,established; classtype:trojan-activity; sid:2025071610; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071611: Detects outbound TCP connection on Sainbox RAT non-standard C2 port 3367
alert tcp $HOME_NET any -> $EXTERNAL_NET 3367 (msg:"SILVERFOX Possible Sainbox RAT C2 on Port 3367"; flow:to_server,established; classtype:trojan-activity; sid:2025071611; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
SID 2025071612: Detects DNS query for Sainbox RAT payload delivery domain 51fapiaoyun.com
alert dns $HOME_NET any -> any any (msg:"SILVERFOX Payload Delivery Domain DNS Lookup - 51fapiaoyun.com"; dns.query; content:"51fapiaoyun.com"; nocase; classtype:trojan-activity; sid:2025071612; rev:1; metadata:created_at 2025_07_16, updated_at 2025_07_16;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon (EventID 7 - Image Loaded) | T1574.002, T1036.005 | Required for DLL side-loading detection. Ensure Sysmon is configured to log DLL loads, particularly for non-standard paths. Index: sysmon, sourcetype: XmlWinEventLog. |
| Sysmon (EventID 13 - Registry Value Set) | T1547.001 | Required for registry persistence detection. Ensure Sysmon configuration includes monitoring of Run key modifications. Index: sysmon, sourcetype: XmlWinEventLog. |
| Sysmon (EventID 6 - Driver Loaded) | T1014 | Required for rootkit and BYOVD driver detection. Must capture driver load events including signature status. Index: sysmon, sourcetype: XmlWinEventLog. |
| Sysmon (EventID 1 - Process Creation) | T1204.002 | Required for detecting execution of malicious MSI installers and Shine.exe. Index: sysmon, sourcetype: XmlWinEventLog. |
| Sysmon (EventID 8 - CreateRemoteThread) | T1055 | Required for detecting reflective DLL injection. Index: sysmon, sourcetype: XmlWinEventLog. |
| Windows System Event Log (EventID 7045) | T1543.003 | Required for detecting Sainbox service creation and driver installation. Index: winevent, sourcetype: WinEventLog. |
| Corelight DNS Logs | T1204.001 | Required for C2 and phishing domain DNS resolution detection. Index: corelight, sourcetype: corelight_dns. |
| Corelight Connection Logs | T1204.001 | Required for detecting outbound connections to C2 IPs on non-standard ports. Index: corelight, sourcetype: corelight_conn. |
| Palo Alto Firewall Logs | T1204.001 | Required for perimeter detection of C2 traffic. Index: firewall-pan, sourcetype: pan:traffic:aggregated and pan:threat. |
| CrowdStrike EDR | T1574.002, T1055, T1014 | Provides DllLoad events and behavioral detections for side-loading and injection. Index: crowdstrike. |
| Sysmon (EventID 11 - File Created) | T1204.002 | Required for detecting creation of 1.txt shellcode container and other file artifacts. Index: sysmon, sourcetype: XmlWinEventLog. |
Recommendations
- Block all confirmed Silver Fox C2 and phishing domains (wpsice.com, fakaka16.top, fakaka9.top, kakafa.top, bifa668.com, 51fapiaoyun.com, rus3rcqtp.hn-bkt.clouddn.com) and infrastructure IPs (45.207.12.71, 154.23.221.136, 206.119.124.126, 118.107.43.65) at DNS resolvers and perimeter firewalls immediately
- Deploy all Sigma, Suricata, and YARA rules from this report across production Splunk, Elastic, network IDS, and endpoint scanning platforms within 48 hours
- Implement AppLocker or WDAC policies to restrict MSI execution from user-writable directories (Downloads, Desktop, %TEMP%, %APPDATA%) to prevent the fake installer initial access vector
- Audit all Windows endpoints for the existence of a service named 'Sainbox' and Registry Run key entries named 'Management', escalating any findings as confirmed compromises
- Hunt retrospectively for BYOVD driver loading events by querying Windows System EventID 7045 and Sysmon EventID 6 for driver names BootRepair.sys, EnPortv.sys, wsftprm.sys, and amsdk.sys across all endpoints
- Brief users who access Chinese-language software portals (WPS Office, Sogou, DeepSeek) and popular messaging applications about the fake installer threat, emphasizing that Silver Fox registers convincing phishing domains that closely match legitimate software download pages
- Ensure Sysmon configuration includes EventID 7 (Image Loaded) logging for DLL side-loading detection, EventID 6 (Driver Loaded) for rootkit/BYOVD detection, and EventID 8 (CreateRemoteThread) for process injection detection, as these are critical telemetry sources for this threat
- Monitor for outbound connections on non-standard ports 3366, 3367, 5040, and 9899, which are used by various Silver Fox RAT variants for C2 communications
Sources
- Netskope - DeepSeek Deception: Sainbox RAT Hidden Rootkit Delivery
- The Hacker News - Chinese Group Silver Fox Uses Fake Software
- SecurityWeek - Chinese Hackers Target Chinese Users with RAT Rootkit
- CyberSecurityNews - Weaponized DeepSeek Installers Delivers Sainbox RAT
- GBHackers - Threat Actors Impersonate WPS Office and DeepSeek
- Proofpoint - Chinese Malware Appears in Earnest Across Cybercrime Threat Landscape
- The Hacker News - Sophisticated Phishing Campaign (Sept 2023)
- The Hacker News - SilverFox Targets Japanese Manufacturer
- The Hacker News - Silver Fox Expands Asia Cyber Campaign
- Sekoia - Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware
- GBHackers - Silver Fox Campaign (Telegram Language Pack)
- MITRE ATT&CK - T1574.002 DLL Side-Loading
- MITRE ATT&CK - T1014 Rootkit
- Netskope Threat Labs IOCs - Sainbox RAT