New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
A new remote access trojan (RAT) called MODBEACON has been discovered, attributed to the China-linked cybercrime group Silver Fox. The malware uses gRPC streaming for encrypted command-and-control (C2) traffic and has been found to be used in a campaign targeting technolo…
Intelligence analysis by Llama

MODBEACON is a Rust-based RAT that uses gRPC streaming for encrypted C2 traffic. It has been found to be used in a campaign targeting technology, education, and state-owned enterprises in Asia. The malware is highly engineered and has a professional and private C2 framework.
Imagine you have a computer that can be controlled by someone else from far away. This is called a remote access trojan, or RAT. MODBEACON is a new type of RAT that uses a special way of communicating with its controller called gRPC streaming. This makes it harder for security software to detect. The people who created MODBEACON are trying to trick people into downloading a fake software installer that actually installs the RAT on their computer.
Analysis
A Sophisticated Threat Actor: Silver Fox and MODBEACON
The China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) called MODBEACON. While the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational structure, which compromises multiple distributors. These distributors conduct activities across Asia using counterfeit software installers distributed through SEO campaigns, leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojan families.
MODBEACON's Capabilities
The core capabilities of MODBEACON include fingerprinting the host, loading plugins in memory, sending heartbeat messages, reporting the results of command execution, and setting persistence using scheduled tasks. This capability can be used for subsequent on-demand expansion of information theft, lateral movement, proxy forwarding, or other payloads.
The Reuse of Open-Source Transport Layer
The overall engineering quality of MODBEACON is high, and its core highlight is the reuse of the transport layer from an open-source anti-censorship proxy framework (Xray/V2Ray) as its C2 channel. This reuse of an existing transport layer is a notable feature of MODBEACON, and it highlights the sophistication of the threat actor behind it.
The Campaign and Its Targets
The newly discovered campaign combines social engineering, custom malware, and post-compromise tooling to establish long-term access while minimizing detection on infected hosts. The memory-resident malware functions as a remote implant capable of fetching additional modules, running operator commands, and maintaining encrypted communications with attacker infrastructure. The campaign targets technology, education, and state-owned enterprises in Asia, and it uses counterfeit domains advertising bogus installers for popular domestic software as lures to trick unsuspecting users into downloading malicious ZIP archives responsible for deploying the malware.
Key points
- MODBEACON is a new Rust-based remote access trojan (RAT) attributed to the China-linked cybercrime group Silver Fox.
- The malware uses gRPC streaming for encrypted command-and-control (C2) traffic.
- MODBEACON has been found to be used in a campaign targeting technology, education, and state-owned enterprises in Asia.
- The malware is highly engineered and has a professional and private C2 framework.
- The campaign uses social engineering, custom malware, and post-compromise tooling to establish long-term access while minimizing detection on infected hosts.
If the development of MODBEACON plays out positively, it could lead to a greater understanding of the threat actor behind it and the techniques they use. This could lead to the development of more effective security measures to detect and prevent the spread of MODBEACON and other similar malware.
The discovery of MODBEACON highlights the ongoing threat of cybercrime groups like Silver Fox, which are actively refining their tradecraft and deploying new malware families. The use of gRPC streaming for encrypted C2 traffic is a notable feature of MODBEACON, and its high engineering quality makes it a concerning development for security professionals. If the development of MODBEACON plays out negatively, it could lead to a greater spread of the malware and a greater risk of cyber attacks.



