# Void Arachne

> As of 2026-09-29, Void Arachne is a China-nexus threat actor tracked by Threadlinqs Intelligence across 11 threats spanning malware, apt. Also known as Silver Fox, 银狐, SilverFox, Silver Fox APT. ATT&CK coverage spans 107 techniques across 14 tactics in 11 of 11 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1055 (Process Injection), T1140 (Deobfuscate/Decode Files or Information).

- **Nation:** China
- **Tracked threats:** 11
- **Categories:** MALWARE, APT
- **Also known as:** Silver Fox, 银狐, SilverFox, Silver Fox APT, SwimSnake-related, Winos 4.0 operators, ValleyRAT operators, SwimSnake, The Great Thief of Valley, Valley Thief, UTG-Q-1000, Great Thief of the Valley
- **As of:** 2026-09-29

## ATT&CK techniques observed

107 techniques observed across 11 of 11 tracked threats. Tactics: Stealth (formerly Defense Evasion) (22), Command and Control (12), Collection (10), Execution (10), Persistence (10), Discovery (9).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 8 of 11 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 8 of 11 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 8 of 11 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 8 of 11 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 7 of 11 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 7 of 11 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 7 of 11 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 7 of 11 tracked threats
- [T1571](https://intel.threadlinqs.com/technique/T1571) Non-Standard Port — Command and Control — observed in 7 of 11 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 6 of 11 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 5 of 11 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 5 of 11 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 5 of 11 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Collection — observed in 5 of 11 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 5 of 11 tracked threats

## Tracked threats

- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2773) — HIGH
- [Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download Sites](https://intel.threadlinqs.com/threat/TL-2026-2283) — HIGH
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — HIGH
- [SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD](https://intel.threadlinqs.com/threat/TL-2026-1787) — HIGH
- [AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)](https://intel.threadlinqs.com/threat/TL-2026-1344) — HIGH
- [SilverFox Deploys ValleyRAT (Go-Based RAT) with Kernel Rootkit AV/EDR Killer](https://intel.threadlinqs.com/threat/TL-2026-1194) — HIGH
- [MODBEACON RAT Uses gRPC Streaming C2, Deployed by Silver Fox via SEO-Poisoned Software Installers](https://intel.threadlinqs.com/threat/TL-2026-1181) — HIGH
- [Atlas RAT — Chinese-Speaking TA4922 Goes Global with RomulusLoader & SilentRunLoader (Europe/Africa Expansion)](https://intel.threadlinqs.com/threat/TL-2026-0680) — HIGH
- [Silver Fox APT Tax-Themed Phishing — RustSL Loader, ValleyRAT & New ABCDoor Python Backdoor](https://intel.threadlinqs.com/threat/TL-2026-0443) — HIGH
- [Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits](https://intel.threadlinqs.com/threat/TL-2026-0276) — HIGH
- [Silver Fox APT Distributes ValleyRAT via Typosquatted Telegram Download Portals](https://intel.threadlinqs.com/threat/TL-2026-0239) — HIGH

## Related CVEs

1 CVE referenced by tracked Void Arachne activity.

- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Void%20Arachne
