Alpha Cyber

Chinese Group “Silver Fox” Uses Fake Sites to Deliver Sainbox RAT & Hidden Rootkit

A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Sainbox Rootkit Graph

A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek. Downloads deliver a weaponized MSI/PE combo: Shine.exe sideloads a malicious libcef.dll that extracts shellcode from 1.txt, loading Sainbox RAT (a Gh0st RAT variant) and an embedded Hidden rootkit, all hidden from view via stealth techniques.

Infrastructure Map

Fake domains: e.g. wpsice[.]com, deepseekai[.]xyz

Phishing vectors: SEO‑poisoning, phishing emails, fake software portals.

Delivery chain: MSI → Shine.exe → libcef.dll → shellcode (1.txt) → Sainbox RAT + Hidden rootkit

Hosting: Cloud platforms like Alibaba Cloud, using Chinese-speaking ASNs 

Visualized in our Threat Intel Tools, this reveals relationships between attacker domains, download files, execution flow, and C2 infrastructure, helping defenders anticipate and block malicious activity.

How Alpha Cyber Can Help

  1. Threat infrastructure mapping with TI tools
  2. Domain and URL filtering to block fake sites
  3. Endpoint protection to detect DLL sideloading and kernel drivers
  4. IOC integration in SIEM/EDR for real-time blocking

🚫 IOC Table: Block or Monitor to Prevent Infection

TypeIndicatorDescription
Domainwpsice[.]comFake WPS installer site (Netskope, The Hacker News, Cloud Industry Review)
deepseekai[.]xyzFake DeepSeek download page
FileShine.exeLoader executable for payload
libcef.dllMalicious DLL for sideloading
1.txtShellcode container file
Hash (SHA256)ba9cf6a733d207df0b35153e37b8963a5c49091ea420fb31786d404ebf4e78d3Sainbox RAT installer

With this proactive mapping and detection, you can defend against Silver Fox’s covert RAT/rootkit attacks before systems are compromised.

Contact us today to deploy infrastructure mapping, IOC blocking, and endpoint defense tailored to your risk profile.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]