news.mlab.sh
Threat intelligence
Threat actor

Void Arachne

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2024-01-01 00:00:00
Motivation
Information theft and espionage
TLP
WHITE

(Trend Micro) In early April, we discovered that a new threat actor group (which we call Void Arachne) was targeting Chinese-speaking users. Void Arachne’s campaign involves the use of malicious MSI files that contain legitimate software installer files for artificial intelligence (AI) software as well as other popular software. The malicious Winos payloads are bundled alongside nudifiers and deepfake pornography-generating AI software, voice-and-face-swapping AI software, zh-CN (Simplified Chinese) language packs, the simplified Chinese version of Google Chrome, and Chinese-marketed virtual private networks (VPNs), such as LetsVPN and QuickVPN. During the process of installation, a Winos backdoor is also installed, which could also lead to full system compromise.

Also known as

Silver Fox

Coverage 13

threat-intel

ValleyRAT masquerading as adware

This report details a sophisticated campaign utilizing adware to distribute the ValleyRAT backdoor. Attackers leveraged a legitimate adware application, signed by a developer, to bypass security measures and install the…

Securelist · Aug 31, 2026 High