A new and highly sophisticated cyberthreat has been added to the already rich arsenal of the notorious Silver Fox, which has been repeatedly linked to attacks attributed to Chinese threat actors. Researchers from cybersecurity firm QiAnXin have revealed the existence of a new Remote Access (RAT) called MODBEACON, which has been developed in the Rust and shows a significantly higher level of technical maturity compared to previous tools from the same group.

The analysis shows that MODBEACON is not a simple malicious program, but a fully modular platform that can be dynamically expanded according to the needs of each attack. The choice of Rust is not considered accidental, as the modern programming language offers high performance, greater stability and makes the analysis of the malware for security experts.
See also: QuimaRAT: New Java RAT targets Windows, Linux and macOS
How does Silver Fox work?
Although Silver Fox has gained a reputation as a group based on massive malware distribution campaigns through fake software installers and SEO poisoning techniques, experts now believe that its real structure is much more organized.
According to QiAnXin, behind the attacks is a network of different malware distributors, operating almost independently but using common infrastructure and tools. These distributors are active in many countries in Asia, using fake websites that appear high in search results and offer supposedly legitimate versions of popular applications.
In fact, the files the user downloads contain Trojans such as Gh0st RAT, ValleyRAT (WinOS) and now MODBEACON, allowing attackers to gain complete control of the computer.
Target businesses and public organizations
The most recent campaign was detected in mid-June 2026 and appears to have primarily targeted technology companies, universities, and state-owned enterprises.
Researchers estimate that the actor behind the attack acts both as a malware distributor and as a “traffic broker,” gaining access to a large number of systems and then renting or selling it to other criminal organizations.
See also: ChocoPoC RAT: Attacks on security researchers via fake PoC repos
In fact, part of his activity appears to be related to criminal networks operating in the illegal online gambling sector in Cambodia, suggesting that the financial motive is combined with cyberespionage operations.
A highly sophisticated spying tool
MODBEACON differs significantly from many conventional RATs, as it operates almost entirely in system memory (memory-resident), significantly reducing the chances of its detection by traditional antiviruses.
Its architecture is separated into loader and beacon, allowing operators to update or replace individual functions without the need to reinstall the malware.
It also uses encrypted communications via gRPC, while leveraging technologies derived from the popular open-source framework Xray/V2Ray. This option allows communication with Command & Control servers to look like normal network traffic, making it even more difficult to detect.
It is also noteworthy that the control server infrastructure is hosted on Amazon and Cloudflare CDN services, leveraging reliable platforms to avoid blockages and increase infrastructure availability.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The capabilities of MODBEACON
According to technical analysis, the new RAT can collect detailed information about the target system, load new add-ons directly into memory, periodically send status messages to the attackers' servers, and transfer the results of the commands it executes.
At the same time, it creates mechanisms for permanent presence in the system through scheduled tasks , ensuring that it will restart even after the computer is restarted.
Its modular design also allows the installation of additional functions depending on the attack objective, such as stealing credentials, collecting sensitive documents, lateral movement into corporate networks, creating proxy nodes, or installing additional payloads.
See also: The renewed Millennium RAT has infected over 62,000 devices
Silver Fox is constantly evolving its arsenal
The appearance of MODBEACON confirms that Silver Fox is no longer limited to well-known malware families, but is actively investing in the development of new tools with increased stealth and remote control capabilities. In recent years, researchers have linked the group to malware such as Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader, indicating a steady effort to upgrade its technology.
For businesses, this development is yet another reminder that modern cyberattacks are now based not only on technical vulnerabilities, but also on user deception. Installing applications exclusively from official sources, using advanced Endpoint Detection & Response (EDR) solutions, continuous staff training and monitoring suspicious network activity are now essential prerequisites for effective protection against increasingly sophisticated threats such as MODBEACON.
