A new malicious campaign has been observed leveraging fake websites advertising popular software, such as WPS Office, Sogou , and DeepSeek, to distribute the remote access tool Sainbox RAT and the open-source rootkit Hidden.
See also: New Chaos RAT variants attack Windows and Linux systems

The activity has been attributed with moderate certainty to a Chinese hacking group known as Silver Fox (also known as Void Arachne), due to similarities in approach technique to previous campaigns attributed to it.
Phishing websites (such as “wpsice[.]com”) appear to be distributing malicious MSI installers in Chinese, suggesting that the campaign is targeting Chinese-speaking users. This is not the first time this group has used this methodology. In July 2024, eSentire described a campaign targeting Chinese-speaking Windows users via fake Google Chrome websites to distribute the Gh0st RAT.
Earlier in February, Morphisec uncovered another campaign that also leveraged fake websites, this time advertising web browsers, to distribute ValleyRAT (also known as Winos 4.0), a different variant of the Gh0st RAT.
See also: Fake DocuSign pages distribute NetSupport RAT malware
ValleyRAT was first recorded by Proofpoint in September 2023, as part of a campaign that also targeted Chinese-speaking users with the Sainbox RAT and Purple Fox.

In the latest wave of attacks detected by Netskope, malicious MSI installers downloaded from websites are designed to execute a legitimate file named “shine.exe”, which uses the DLL side-loading technique to load a malicious DLL file named “libcef.dll”.
The main purpose of the DLL is to extract shellcode from a text file named “1.txt” included in the installer and then execute it. This process ultimately leads to the execution of another malicious DLL, which is a remote access tool (RAT) called Sainbox.
While Sainbox has features for downloading additional malicious payloads and stealing data, Hidden offers attackers a number of concealment mechanisms, allowing them to hide malware-related processes as well as Windows Registry keys on infected computers.
See also: Malware analysis reveals sophisticated RAT
The use of tools such as Sainbox RAT and Hidden rootkit shows that the ultimate goal of the attacks is not only the initial breach but also maintaining access to the system (persistence) and collecting information over time — characteristics of a cyber espionage campaign.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
