type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [rat, c2, loader] ยท confidence: medium ยท affected_sectors: [technology, education, government] ยท au_impact: false
MODBEACON RAT
MODBEACON is a Rust-based remote access trojan (RAT) attributed by Qianxin Threat Intelligence to the China-linked Silver Fox cybercrime group. It uses gRPC streaming for encrypted command-and-control (C2) communication โ a relatively modern and stealthy C2 channel.
Technical Details
- Language: Rust
- C2 protocol: gRPC streaming (encrypted)
- Infrastructure: Hosted on Amazon (AWS) and Cloudflare CDN
- Advanced C2: gRPC provides bidirectional streaming with native encryption, making traffic analysis harder
Distribution
- SEO poisoning โ victims search for legitimate software and find counterfeit installer sites
- Targets technology, education, and state-owned enterprises across Asia (raw/digests/Cyber-Digest-2026-07-11)
Related Pages
- Silver Fox โ The threat group operating this malware
- Longleash โ Another China-linked malware (targets networking devices)
- Gigawiper โ Destructive backdoor with different objectives