Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. "The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonating brands including Surfshark VPN, Signal, Telegram, Zoom, Microsoft Teams, and others," Germany-based cybersecurity company Hexastrike said in a report published last week. The activity has been attributed to a Chinese cybercrime group called Silver Fox, which is also tracked as SwimSnake, The Great Thief of Valley (or Valley Thief), UTG-Q-1000, and Void Arachne. The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins). The attack chains involve using bogus websites as lures to trick users into downloading ZIP archives containing an installer that drops a trojanized Autodesk binary along with the legitimate decoy application. The trojanized AutoDesk installer, in turn, launches a shellcode loader that decrypts an embedded Gh0st RAT configuration to extract the command-and-control (C2) details and then downloads a second-stage shellcode payload from "bifa668[.]com" over TCP on port 9899, ultimately leading to the execution of AtlasCross RAT in memory. The majority of fake websites were registered in a single day on October 27, 2025, indicating a deliberate approach behind the campaign. The list of confirmed malware delivery domains is listed below - - app-zoom.com (Zoom) - eyy-eyy.com (unknown) - kefubao-pc.com (KeFuBao, a Chinese customer service software for e-commerce) - quickq-quickq.com (QuickQ VPN) - signal-signal.com (Signal) - telegrtam.com.cn (Telegram) - trezor-trezor.com (Trezor) - ultraviewer-cn.com (UltraViewer) - wwtalk-app.com (WangWang) - www-surfshark.com (Surfshark VPN) - www-teams.com (Microsoft Teams) All identified installer packages have been found to carry the same stolen Extended Validation code-signing certificate
Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains
Read the original article
thehackernews.com →