CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2318

As cited

Copy frozen at (site build).

threat intel

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

Silver Fox, a China-linked cybercrime group, has deployed a new Rust-based remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-control traffic. The group distributes malware through counterfeit installers and SEO poisoning despite appearing as a low-sophistication operation.

Why it matters: Organizations targeted by SEO poisoning and counterfeit software downloads face infection with a difficult-to-detect RAT; monitor for gRPC-based C2 traffic and validate software authenticity before installation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary