# Silver Fox APT

> As of 2026-05-30, Silver Fox APT is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware, apt. Also known as SilverFox, Silver Fox, Void Arachne, ValleyRAT operators. ATT&CK coverage spans 60 techniques across 12 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1055 (Process Injection), T1082 (System Information Discovery).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** MALWARE, APT
- **Also known as:** SilverFox, Silver Fox, Void Arachne, ValleyRAT operators, Winos 4.0 operators, ValleyRAT Group, Winos4.0 Operators
- **As of:** 2026-05-30

## ATT&CK techniques observed

60 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (14), Execution (10), Collection (7), Command and Control (7), Discovery (5), Initial Access (4).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 2 of 3 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1115](https://intel.threadlinqs.com/technique/T1115) Clipboard Data — Collection — observed in 2 of 3 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 2 of 3 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 2 of 3 tracked threats
- [T1218.011](https://intel.threadlinqs.com/technique/T1218.011) Rundll32 — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1497.001](https://intel.threadlinqs.com/technique/T1497.001) Virtualization/Sandbox Evasion: System Checks — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats

## Tracked threats

- [Fake Microsoft Teams Sites Deliver ValleyRAT via NSIS Installer and DLL Sideloading of Tencent GameBox.exe (Silver Fox APT)](https://intel.threadlinqs.com/threat/TL-2026-0538) — HIGH
- [Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python Backdoor](https://intel.threadlinqs.com/threat/TL-2026-0443) — HIGH
- [ValleyRAT via Fake Huorong AV Site — Silver Fox APT DLL Sideloading, Winos4.0 Framework, Encrypted Shellcode Persistence](https://intel.threadlinqs.com/threat/TL-2026-0138) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Silver%20Fox%20APT
