Chinese Group “Silver Fox” Uses Fake Sites to Deliver Sainbox RAT & Hidden Rootkit
A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek.

A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek. Downloads deliver a weaponized MSI/PE combo: Shine.exe sideloads a malicious libcef.dll that extracts shellcode from 1.txt, loading Sainbox RAT (a Gh0st RAT variant) and an embedded Hidden rootkit, all hidden from view via stealth techniques.
Infrastructure Map
Fake domains: e.g. wpsice[.]com, deepseekai[.]xyz
Phishing vectors: SEO‑poisoning, phishing emails, fake software portals.
Delivery chain: MSI → Shine.exe → libcef.dll → shellcode (1.txt) → Sainbox RAT + Hidden rootkit
Hosting: Cloud platforms like Alibaba Cloud, using Chinese-speaking ASNs
Visualized in our Threat Intel Tools, this reveals relationships between attacker domains, download files, execution flow, and C2 infrastructure, helping defenders anticipate and block malicious activity.
How Alpha Cyber Can Help
- Threat infrastructure mapping with TI tools
- Domain and URL filtering to block fake sites
- Endpoint protection to detect DLL sideloading and kernel drivers
- IOC integration in SIEM/EDR for real-time blocking
🚫 IOC Table: Block or Monitor to Prevent Infection
| Type | Indicator | Description |
|---|---|---|
| Domain | wpsice[.]com | Fake WPS installer site (Netskope, The Hacker News, Cloud Industry Review) |
deepseekai[.]xyz | Fake DeepSeek download page | |
| File | Shine.exe | Loader executable for payload |
libcef.dll | Malicious DLL for sideloading | |
1.txt | Shellcode container file | |
| Hash (SHA256) | ba9cf6a733d207df0b35153e37b8963a5c49091ea420fb31786d404ebf4e78d3 | Sainbox RAT installer |
With this proactive mapping and detection, you can defend against Silver Fox’s covert RAT/rootkit attacks before systems are compromised.
Contact us today to deploy infrastructure mapping, IOC blocking, and endpoint defense tailored to your risk profile.



