This report highlights two separate threat activities associated with the groups Silver Fox and Stealth Falcon. It outlines effective methods for analyzing and tracking their operations using the ANY.RUN’s solutions, including malware behavior analysis in the sandbox and enrichment of the investigation via TI Lookup. The report provides IOCs, TTPs, adversary profiles, and technical context for each activity. The content is intended to support threat hunting and attribution efforts across distinct threat scenarios.
A recent investigation by Check Point Research uncovered a sophisticated attack attributed to the Stealth Falcon APT group. The campaign exploits a previously unknown zero-day vulnerability CVE-2025-33053 to deliver custom malware via malicious .url shortcut files.
Stealth Falcon is a UAE-aligned APT group, also known as FruityArmor, active since at least 2012. It conducts cyberespionage operations primarily targeting government-related entities, journalists, and media organizations.
Origin: United Arab Emirates
Active Since: 2012
Motivation: Espionage, Information Theft
Targeted Countries: Saudi Arabia, Egypt, Qatar, Yemen, Turkey, United Kingdom, Netherlands, Thailand
Targeted Industries: Government, Media, Civil Society, Diplomacy
The first-stage payload is a specially crafted .url file that abuses CVE‑2025‑33053 to hijack the behavior of iediagcmd.exe. When executed, it redirects this built-in Windows utility to connect to a remote WebDAV server under the attacker’s control, where it retrieves and launches a malicious loader.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
filePath:"*.url" and threatName:"webdav" AND commandLine:"iediagcmd.exe"
We identified samples of the .url file using ANY.RUN TI Lookup.
ba5beb189d6e1811605b0a4986b232108d6193dcf09e5b2a603ea4448e6f263cAfter the CVE-2025-33053 vulnerability is exploited via the crafted .url file, the system executes a remote binary route.exe from a WebDAV server under the attacker’s control. This file serves as Horus Loader, a custom component attributed to Stealth Falcon.
Horus Loader is designed to open the PDF decoy, terminate related processes, and facilitate the delivery of the final payload — Horus Agent.
da3bb6e38b3f4d83e69d31783f00c10ce062abd008e81e983a9bd4317a9482aa
Within the Horus Loader code, a logic error appears to cause the use of incorrect variable values when attempting to terminate processes associated with the earlier execution stage. As a result, instead of targeting actual process names, the loader issues malformed taskkill commands:
taskkill.exe /IM i /Ftaskkill.exe /IM e /F
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"taskkill /IM i /F" or commandLine:"taskkill /IM e /F"
A recent technical analysis by Netskope Threat Labs uncovered a campaign linked to the Silver Fox APT group. The attackers used fake installers for widely used software like DeepSeek, Sogou, and WPS Office to deploy the Sainbox RAT, a variant of Gh0stRAT, together with a Hidden rootkit.
Silver Fox is a China-based APT group, also known as Void Arachne. Since 2024, it has been conducting active malware distribution campaigns through fake websites impersonating popular software.
Origin: China
Active Since: 2024
Motivation: Espionage, Information Theft
Targeted Countries: China, Taiwan, Japan
Targeted Industries: Government, Industrial, Healthcare, General Public
Initial access is obtained through phishing websites, where the victim is tricked into downloading a malicious MSI installer disguised as legitimate software such as DeepSeek, Sogou, or WPS Office.
We can analyze a sample of the installer impersonating DeepSeek using the ANY.RUN sandbox.
55cd22e7f8fa3cea78fb4aff441cb167a68c37441376c3fb9dc3d48ea21d465aAs part of the execution chain, shine.exe is launched to load a malicious libcef.dll. Additionally, a file named 1.txt is dropped. It contains the payload and shellcode that is executed.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"Shine.exe" AND filePath:"libcef.dll"
Additionally, we can observe how msiexec.exe, as part of its standard procedure, adds registry entries referencing the files shine.exe libcef.dll and 1.txt. Despite the legitimacy of this process, the files themselves are malicious.

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
commandLine:"msiexec.exe" AND (registryValue:"C:\\ProgramData\\*\\Shine.exe" OR registryValue:"C:\\ProgramData\\*\\libcef.dll" or registryValue:"1.txt")
ANY.RUN allows us to observe that Shine.exe runs with an untrusted certificate and establishes persistence via a Run key in the registry. The executable is dropped to C:\ProgramData\Deepseek\Shine.exe under the name Management. The analysis also reveals functionality for taking screenshots, detecting crypto addresses, and C2 communication to 154.23.221.136:1805 over a non-standard TCP port. Additional indicators such as file paths, registry keys, and network metadata can also be collected.

In this sample, the "Network threats" section of the ANY.RUN analysis reveals detections for Gh0stRAT and its variant Gh0stCringe, confirming active C2 communication with known malware infrastructure.
8be316e9308a263fb890d2847d46b9db59a42e76997dfbc7c7c91a46b0520fc9
This report covers two separate cases involving recent activity by the groups Stealth Falcon and Silver Fox, highlighting IOCs, malware samples, and execution techniques specific to each. Using ANY.RUN, we demonstrated how analysts can investigate such threats and search for related activity. These capabilities help expand understanding of each threat, reveal additional indicators, and support informed defensive actions.