Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [rat, c2, loader] ยท confidence: medium ยท affected_sectors: [technology, education, government] ยท au_impact: false

MODBEACON RAT

MODBEACON is a Rust-based remote access trojan (RAT) attributed by Qianxin Threat Intelligence to the China-linked Silver Fox cybercrime group. It uses gRPC streaming for encrypted command-and-control (C2) communication โ€” a relatively modern and stealthy C2 channel.

Technical Details

  • Language: Rust
  • C2 protocol: gRPC streaming (encrypted)
  • Infrastructure: Hosted on Amazon (AWS) and Cloudflare CDN
  • Advanced C2: gRPC provides bidirectional streaming with native encryption, making traffic analysis harder

Distribution

  • SEO poisoning โ€” victims search for legitimate software and find counterfeit installer sites
  • Targets technology, education, and state-owned enterprises across Asia (raw/digests/Cyber-Digest-2026-07-11)

Related Pages

  • Silver Fox โ€” The threat group operating this malware
  • Longleash โ€” Another China-linked malware (targets networking devices)
  • Gigawiper โ€” Destructive backdoor with different objectives