CyberSecurityBoardThreat Intel · CVEs · Products
Malware

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

July 10, 2026

The China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) called MODBEACON. Chinese cybersecurity company QiAnXin reported that the threat cluster, while appearing as a low-sophistication, high-activity operation using SEO poisoning and counterfeit installers, actually comprises multiple distributors operating across Asia.

One campaign observed in mid-June 2026 involved a distributor delivering a modular RAT targeting technology, education, and state-owned enterprises. MODBEACON’s command-and-control (C2) infrastructure is hosted on Amazon and Cloudflare’s CDN. The distributor is assessed as a hybrid threat actor, acting as a cybercriminal arms dealer and traffic broker, expanding infection via SEO for fraud and propagating advanced trojans or renting access to downstream customers.

The memory-resident malware functions as a remote implant capable of fetching modules, running commands, and maintaining encrypted communications. It uses gRPC tunnel streaming for communication and reuses the transport layer from the open-source anti-censorship proxy framework Xray/V2Ray. Core capabilities include host fingerprinting, loading plugins in memory, sending heartbeats, reporting command execution results, and setting persistence via scheduled tasks.

The disclosure comes amid Silver Fox’s broadening arsenal, which includes Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader, indicating active refinement of tradecraft.

CVEs: CVE-2026-55200, CVE-2026-46817

Attack groups: Silver Fox

Malware: MODBEACON, Gh0st RAT, WinOS (ValleyRAT), Atlas RAT, ABCDoor, RomulusLoader, SilentRunLoader

Companies: QiAnXin, Amazon, Cloudflare