As cited
Copy frozen at (site build).
threat intel
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Silver Fox, a China-linked cybercrime group, has deployed a new Rust-based remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-control traffic. The group distributes malware through counterfeit installers and SEO poisoning despite appearing as a low-sophistication operation.
Why it matters: Organizations targeted by SEO poisoning and counterfeit software downloads face infection with a difficult-to-detect RAT; monitor for gRPC-based C2 traffic and validate software authenticity before installation.
- Source published
- First seen by Cybersecurity Tracker