Unauthorized news on hackers, data breaches, zero-day exploits, ransomware and AI. Original reporting and analysis for people who actually read the source.

Hackers

Silver Fox Levels Up: The Chinese Crew Switches to Rust

Known for its fake installers, the China-linked group Silver Fox has a new tool, MODBEACON. Judging by the engineering, the fox is done playing the amateur.

Silver Fox Levels Up: The Chinese Crew Switches to Rust

The Chinese firm QiAnXin attributed a new Rust-based remote access trojan named MODBEACON to the Silver Fox group in mid-June 2026. The Hacker News reported the analysis first. In years of watching this group, few analysts have called it technically sophisticated. MODBEACON forces a rethink.

Who Silver Fox are

Silver Fox, also tracked as Void Arachne, is known to analysts as a China-linked APT group with a dual mandate. Part of its work looks like state espionage, part like ordinary cybercrime that appears to fund the rest. The arrangement buys what the intelligence world calls plausible deniability: no direct budget lines to point at, and the work still gets done.

The group hits China above all, along with Chinese-speaking users, including staff at Western companies with offices in the country. The playbook is recognizable: SEO poisoning, fake Microsoft Teams and Telegram installers, look-alike domains such as teamscn.com. One detail lands with some irony on a site like ours: Silver Fox has more than once salted its code with Cyrillic characters to lead analysts down a false trail. Attribution, as always, calls for caution.

What is new in MODBEACON

The group's older arsenal, Gh0st RAT and ValleyRAT (also known as WinOS), has been familiar to defenders for a long time. MODBEACON is built differently. It is a memory-resident implant: it runs entirely in the memory of 64-bit Windows and leaves none of the usual traces on disk, which makes life harder for antivirus tools. The architecture is modular, with loadable plugins and an injectable configuration. The feature set is standard for a modern RAT: host fingerprinting, plugin loading, heartbeat signals, reports on executed commands and persistence through scheduled tasks. What stands out is not the capability but the execution.

Stealth on legitimate infrastructure

The most interesting part is how MODBEACON talks to its command server. The trojan uses gRPC over HTTP/2, and the whole channel is wrapped in TLS, so to a network monitor it looks like ordinary encrypted web traffic. The group runs its command infrastructure on the Amazon and Cloudflare CDNs. The logic is plain: blocking that traffic without hitting legitimate services is hard, and the malicious flow simply disappears into the general stream.

Same door, new guest

The delivery method, meanwhile, stayed down to earth. Victims are still lured to a counterfeit site and handed a ZIP archive posing as the software they wanted, with a network of distributors handling the spread across Asia. In the June campaign, MODBEACON reached companies in technology, education and the state sector.

That is the heart of the story. There is nothing new in how Silver Fox lures people in. What is new is what follows them through the door. The move to Rust, to running in memory and to hiding inside cloud traffic is something we have watched spread across the field over the past couple of years, from ransomware crews to state brigades. Silver Fox has simply joined the line. For defenders the takeaway is uncomfortable: catching a threat like this by a file on disk or a suspicious domain is already too late. The place to look is behavior.

Based on research by QiAnXin, ReliaQuest and The Hacker News.

Share this article
Share

Written by

Martin
Martin
Editor of Russian Hackers. Unauthorized news on hackers, breaches, exploits and AI.

Read next

Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds

Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds

In the first half of 2026, attackers stole about $972 million from the cryptocurrency industry across 207 incidents, according to a mid-year report from analytics firm TRM Labs. The figure is down by more than half from the same period in 2025, when losses were put at $2.3 billion. Despite the overall decline, the share tied to North Korea has actually grown. Analysts attribute roughly $643 million, about 66% of the half-year total, to the Lazarus Group and its TraderTraitor subunit. Almost all
By Martin

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Comic-poster cover: a cracked security shield shattering under 570 flaws and two zero-days

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Comic-poster cover: a hacker prying open a Windows registry hive, the LegacyHive zero-day