HomeSecurityMODBEACON RAT: gRPC streaming for encrypted C2 communication

MODBEACON RAT: gRPC streaming for encrypted C2 communication

A new and highly sophisticated cyberthreat has been added to the already rich arsenal of the notorious Silver Fox, which has been repeatedly linked to attacks attributed to Chinese threat actors. Researchers from cybersecurity firm QiAnXin have revealed the existence of a new Remote Access (RAT) called MODBEACON, which has been developed in the Rust and shows a significantly higher level of technical maturity compared to previous tools from the same group.

Article Image: New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The analysis shows that MODBEACON is not a simple malicious program, but a fully modular platform that can be dynamically expanded according to the needs of each attack. The choice of Rust is not considered accidental, as the modern programming language offers high performance, greater stability and makes the analysis of the malware for security experts.

See also: QuimaRAT: New Java RAT targets Windows, Linux and macOS

How does Silver Fox work?

Although Silver Fox has gained a reputation as a group based on massive malware distribution campaigns through fake software installers and SEO poisoning techniques, experts now believe that its real structure is much more organized.

According to QiAnXin, behind the attacks is a network of different malware distributors, operating almost independently but using common infrastructure and tools. These distributors are active in many countries in Asia, using fake websites that appear high in search results and offer supposedly legitimate versions of popular applications.

In fact, the files the user downloads contain Trojans such as Gh0st RAT, ValleyRAT (WinOS) and now MODBEACON, allowing attackers to gain complete control of the computer.

Target businesses and public organizations

The most recent campaign was detected in mid-June 2026 and appears to have primarily targeted technology companies, universities, and state-owned enterprises.

Researchers estimate that the actor behind the attack acts both as a malware distributor and as a “traffic broker,” gaining access to a large number of systems and then renting or selling it to other criminal organizations.

See also: ChocoPoC RAT: Attacks on security researchers via fake PoC repos

In fact, part of his activity appears to be related to criminal networks operating in the illegal online gambling sector in Cambodia, suggesting that the financial motive is combined with cyberespionage operations.

A highly sophisticated spying tool

MODBEACON differs significantly from many conventional RATs, as it operates almost entirely in system memory (memory-resident), significantly reducing the chances of its detection by traditional antiviruses.

Its architecture is separated into loader and beacon, allowing operators to update or replace individual functions without the need to reinstall the malware.

It also uses encrypted communications via gRPC, while leveraging technologies derived from the popular open-source framework Xray/V2Ray. This option allows communication with Command & Control servers to look like normal network traffic, making it even more difficult to detect.

It is also noteworthy that the control server infrastructure is hosted on Amazon and Cloudflare CDN services, leveraging reliable platforms to avoid blockages and increase infrastructure availability.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

MODBEACON RAT: gRPC streaming for encrypted C2 communication

The capabilities of MODBEACON

According to technical analysis, the new RAT can collect detailed information about the target system, load new add-ons directly into memory, periodically send status messages to the attackers' servers, and transfer the results of the commands it executes.

At the same time, it creates mechanisms for permanent presence in the system through scheduled tasks , ensuring that it will restart even after the computer is restarted.

Its modular design also allows the installation of additional functions depending on the attack objective, such as stealing credentials, collecting sensitive documents, lateral movement into corporate networks, creating proxy nodes, or installing additional payloads.

See also: The renewed Millennium RAT has infected over 62,000 devices

Silver Fox is constantly evolving its arsenal

The appearance of MODBEACON confirms that Silver Fox is no longer limited to well-known malware families, but is actively investing in the development of new tools with increased stealth and remote control capabilities. In recent years, researchers have linked the group to malware such as Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader, indicating a steady effort to upgrade its technology.

For businesses, this development is yet another reminder that modern cyberattacks are now based not only on technical vulnerabilities, but also on user deception. Installing applications exclusively from official sources, using advanced Endpoint Detection & Response (EDR) solutions, continuous staff training and monitoring suspicious network activity are now essential prerequisites for effective protection against increasingly sophisticated threats such as MODBEACON.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS