Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

Silver Fox group uses new Rust-based MODBEACON RAT

  • What: Silver Fox group uses new Rust-based MODBEACON RAT
  • Impact: Targets enterprises in technology, education, and state sectors
Read Full Article →

Malware Silver Fox group uses new Rust-based MODBEACON RAT July 10, 2026 Share By SC Staff (Adobe Stock) Per The Hacker News, the China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) named MODBEACON, which is being used to target technology, education, and state-owned enterprises. QiAnXin, a Chinese cybersecurity company, reported that while the group's operations may appear unsophisticated due to the use of SEO poisoning and counterfeit software installers, their organizational structure is more complex, involving multiple distributors. These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans. One observed campaign in mid-June 2026 involved a distributor delivering MODBEACON, which utilizes Amazon and Cloudflare's CDN for its command-and-control infrastructure. The distributor is described as a hybrid threat actor, acting as both a "cybercriminal arms dealer" and "traffic broker." MODBEACON is a memory-resident implant capable of fetching additional modules, executing commands, and maintaining encrypted communications. It features a modular design, an injectable configuration, and uses a plugin-based architecture. The attack chain employs social engineering and counterfeit domains to trick users into downloading malicious ZIP archives. MODBEACON's capabilities include host fingerprinting, plugin loading, sending heartbeat messages, reporting command execution results, and establishing persistence through scheduled tasks. This new development indicates Silver Fox is actively refining its tradecraft, expanding its arsenal with malware families like Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader. Source: The Hacker News SC Staff Related Malware Threat actor uses AI-generated malware in network intrusion SC Staff July 9, 2026 The AI-generated tool, titled "100% Working AD Information Gathering Script - FULLY FIXED," exhibited several hallmarks of LLM assistance, including a placeholder server name, over-engineering with multiple fallback methods, and a "pretty" console output using excessive colors, Huntress said. Malware Microsoft details GigaWiper destructive backdoor assembled from older tools SC Staff July 9, 2026 GigaWiper, written in Go, operates on Windows and presents operators with numbered commands, three of which are designed for system destruction. Malware New GoodPersonRAT malware distributed via fake LetsVPN installer SC Staff July 9, 2026 The trojanized installer, identified as Kuailian_win-setup.86.msi, embeds a loader and an encrypted payload alongside the authentic LetsVPN application. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article