Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-03

Void Arachne

Also known as:Silver Fox银狐SilverFoxSilver Fox APTSwimSnake-relatedWinos 4.0 operatorsValleyRAT operatorsSwimSnakeThe Great Thief of ValleyValley ThiefUTG-Q-1000Great Thief of the Valley

As of 2026-09-29, Void Arachne is a China-nexus threat actor tracked by Threadlinqs Intelligence across 11 threats spanning malware, apt. Also known as Silver Fox, 银狐, SilverFox, Silver Fox APT. ATT&CK coverage spans 107 techniques across 14 tactics in 11 of 11 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1055 (Process Injection), T1140 (Deobfuscate/Decode Files or Information).

Tracked threats
1111 high
First seen
2026-03-17
Last seen
2026-09-29
ATT&CK techniques
107across 11 of 11 threats
Related CVEs
1Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 11 tracked threat(s) · Categories: MALWARE, APT

Activity timeline

Void Arachne appears in 11 tracked threats between and ; the busiest month was 2026-07 with 4 reports.

ATT&CK techniques observed

107 techniques observed across 11 of 11 tracked threats · Stealth (formerly Defense Evasion) (22), Command and Control (12), Collection (10), Execution (10), Persistence (10), Discovery (9)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
  • T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 8 of 11 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 8 of 11 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 7 of 11 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 7 of 11 tracked threats
  • T1112 Modify Registry — Defense Impairmentobserved in 7 of 11 tracked threats
  • T1566 Phishing — Initial Accessobserved in 7 of 11 tracked threats
  • T1571 Non-Standard Port — Command and Controlobserved in 7 of 11 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 6 of 11 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 5 of 11 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 5 of 11 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 5 of 11 tracked threats
  • T1056 Input Capture — Collectionobserved in 5 of 11 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 5 of 11 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Void Arachne activity