Activity timeline
Void Arachne appears in 11 tracked threats between and ; the busiest month was 2026-07 with 4 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 8 of 11 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 7 of 11 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 7 of 11 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 7 of 11 tracked threats
- T1566 Phishing — Initial Accessobserved in 7 of 11 tracked threats
- T1571 Non-Standard Port — Command and Controlobserved in 7 of 11 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 6 of 11 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 5 of 11 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 5 of 11 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 5 of 11 tracked threats
- T1056 Input Capture — Collectionobserved in 5 of 11 tracked threats
- T1057 Process Discovery — Discoveryobserved in 5 of 11 tracked threats
Tracked threats
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows DefensesHIGH
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download SitesHIGH
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL SideloadingHIGH
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDHIGH
- AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)HIGH
- SilverFox Deploys ValleyRAT (Go-Based RAT) with Kernel Rootkit AV/EDR KillerHIGH
- MODBEACON RAT Uses gRPC Streaming C2, Deployed by Silver Fox via SEO-Poisoned Software InstallersHIGH
- Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion)HIGH
- Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python BackdoorHIGH
- Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel RootkitsHIGH
- Silver Fox APT Distributes ValleyRAT via Typosquatted Telegram Download PortalsHIGH