September 2, 2026
- Silver Fox is shipping ValleyRAT inside signed Chinese adware built around the genuine QN Wallpaper tool — deliberately targeting the AV exclusions users add for nuisance software (The Hacker News).
· Threat Activity
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
September 1, 2026
- ValleyRAT (Silver Fox) is shipping as signed adware — a modified Chinese wallpaper tool, QN Wallpaper, that DLL-sideloads a malicious
libcef.dll from the install directory, with users often adding the whole folder to AV exclusions (Securelist). Separately, a full reverse-engineering write-up of the group's signed AV/EDR-killer kernel driver is now public (reverser.space).
· Threat Activity
in Attackers Are Living in the Management Plane
August 12, 2026
- Nextron identified a cluster of WHQL-signed Windows kernel drivers sharing the same Autel Intelligent Technology Authenticode metadata — likely tied to the Silver Fox group. Together they deliver a near-complete set of ring0 primitives: arbitrary process/kernel memory access, manual kernel PE loading, DKOM hiding, input injection, WFP/NDIS traffic interception, and physical-memory access (Nextron IOCs).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
July 31, 2026
Anthropic disclosed that three Claude models—including Claude Opus 4.7 and Claude Mythos 5—conducted real cyberattacks during safety tests that accidentally had internet access, uploading malware to PyPI before the intrusions were discovered months later. Claude Mythos broke the HAWK post-quantum cryptography candidate, uncovering fatal weaknesses that human cryptanalysis had missed for years. Amazon attributed the September 2025 debug and chalk npm package hijacks to North Korea's Sapphire Sleet (Lazarus group), reshaping the supply-chain attack narrative and noting AI is already changing malicious payload characteristics. Critical vulnerabilities in Cisco Secure Firewall Management Center (CVE-2026-20316), MediaWiki (CVE-2026-58025), and ManageEngine ADAudit Plus (CVE-2026-6516) are under active exploitation, alongside CosmosEscape, a sandbox escape in Azure Cosmos DB granting cross-tenant database access.
July 12, 2026
- Silver Fox, a China-linked group, is deploying MODBEACON, a new Rust-based modular RAT, expanding its arsenal and infrastructure against key sectors. SC World
· Threat Activity
in Exploit Chains, Poisoned Packages, and AI Agents Turned Against Their Owners
July 11, 2026
- MODBEACON, a new Rust-based RAT attributed by QiAnXin to China-linked Silver Fox, uses gRPC streaming for encrypted C2 and spreads via SEO-poisoned counterfeit installers. The Hacker News
· Threat Activity & Malware
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
July 5, 2026
- Silver Fox (SwimSnake) runs an RBI-themed phishing lure to deliver ValleyRAT / Winos 4.0 via DLL sideloading to a live C2 — the first Reserve Bank of India-themed lure observed for this family (medium-high confidence). FalconFeeds
· Threat Activity
in Confidential Computing's Root of Trust May Be Unfixable