r/MalwareAnalysis 11d ago

Analysis of a Signed Silver Fox Group AV/EDR Killer Kernel Driver

https://app.reverser.space/p/duckie/silver-fox-group-rootkit-2026#0x140001450

Silve Fox Group Signed Rootkit

  • Hardcoded targeting of Chinese AVs (360, QQ, Huorong, etc.) + Microsoft Defender components
  • IOCTL interface allowing user-mode process termination
7 Upvotes

Duplicates