Chinese Malware Delivery Domains Part V

Published on: 
August 19, 2026

Introduction

In Parts I-IV of this series, we reported on a large-scale malware delivery network targeting Chinese speaking users. This cluster is frequently associated with the Silver Fox threat group and relies on thousands of typo-squatted domains. We noted previously that this infrastructure appeared to operate under an affiliate or Malware as a Service (MaaS) model. In mid June 2026, Chinese law enforcement reportedly arrested several individuals connected to Silver Fox operations. Despite this, the delivery network remained active. Multiple distinct affiliates continued registering hundreds of new malicious domains just days after the arrests. To keep these new campaigns online, the operators are blending localized .com.cn domains with abused legitimate services. We are currently tracking payloads hosted on GitHub release assets, Microsoft Store redirects, and enterprise cloud buckets across AWS, Google Cloud, and Alibaba.

The attackers behind these campaigns use software trends to maximize their infection rates. Their targeting changes based on whatever applications are currently dominating the Chinese market. Two years ago, their landing pages primarily spoofed web browsers and VPNs. Over the past year, they have capitalized heavily on the artificial intelligence boom by distributing fake installers for DeepSeek and Doubao. Regardless of the affiliate or the specific software being spoofed, the underlying infection chain identified in this campaign looks nearly identical. Victims receive a heavily modified Gh0stRAT variant hidden inside installers padded to over 100MB, which allows the malware to bypass file size limits on automated sandboxes. The execution process involves OLLVM obfuscation, a UAC bypass, and Reflective DLL Injection (sRDI) to load the malware directly into legitimate system processes. Once active, the payload communicates with its command and control servers using a custom network stack built on the hp-worker library.

Infrastructure and Lure Variations

Continuous monitoring of this cluster indicates the actor is rapidly diversifying both their distribution methods and their malware lures. While previous campaigns relied heavily on newly registered domains (NRDs), recent activity shows a systemic integration of abused legitimate services to bypass DNS reputation filtering. Analysis of the delivery URLs indicates the actor is hosting payloads across major cloud providers. Observed infrastructure used by the actor previously includes Alibaba Cloud OSS (doubaoaa.oss-cn-hongkong.aliyuncs[.]com), AWS S3 (dfgdhgg.s3.ap-east-1.amazonaws[.]com), and Google Cloud Storage (storage.googleapis[.]com). Additionally, the actor utilizes dynamic linking services like Branch.io (app[.]link), manipulates GitHub release assets, and abuses Microsoft Store search redirects (apps.microsoft[.]com).

To build trust on their landing pages, the actor frequently includes legitimate links to the Apple App Store and Google Play Store for mobile users, while serving the malicious payloads strictly to users downloading the Windows or macOS desktop executables.

Expansion of Spoofed Targets
While the actor continues to target users seeking foreign access and trading platforms (ProtonVPN, NordVPN, MetaTrader 5, AICoin), they are increasingly spoofing domestic Chinese software.

Notable additions to the spoofing infrastructure include:

  • Artificial Intelligence: Capitalizing on current trends, the actor has registered domains spoofing DeepSeek (ai-deepseekapp[.]com[.]cn) and Doubao AI.

  • Enterprise and Productivity: Lures include DingTalk (Alibaba’s enterprise communication platform), Baidu Netdisk, and Quark Browser.

  • Security Software: The actor is distributing payloads masquerading as Huorong Security (down.app-huorong[.]cn), a widely used Chinese antivirus and endpoint protection platform.

Post-Arrest and the Affiliate Model

In mid-June 2026, reports indicated that Chinese law enforcement executed arrests targeting operators associated with the Silver Fox malware campaigns. However, pivot analysis of the domain infrastructure reveals that these campaigns continue to be active.

Between June 17 and June 27, 2026, over 400 new malicious domains were registered and provisioned with active hosting. This sustained operational tempo validates a hypothesis generated in Part IV of this series: the malware delivery "super-cluster" operates as a decentralized Malware-as-a-Service (MaaS) platform. Rather than a single monolithic threat actor, the infrastructure is utilized by multiple distinct affiliates or operators who bring their own lures and targeting preferences while utilizing a shared baseline of Gh0stRAT-style payloads and obfuscation tooling.

Infrastructure pivot analysis isolates at least three highly distinct operational profiles active in the post-arrest window:

Cluster 1:
The most prolific active cluster is operated by an entity utilizing the email 7cf560423@baituo[.]io and the registrant name "徐涛" (Xu Tao). This operator registered 322 domains in the 10 days following the reported arrests.

  • TTPs: This operator utilizes a highly rigid, automated infrastructure deployment model. They provision exactly one dedicated Alibaba Cloud HK IP address per spoofed brand campaign. For example, all recent Surfshark lures resolve to 8[.]210[.]120[.]164, Kraken Exchange lures to 47[.]239[.]173[.]17, and Baidu Wangpan lures to 8[.]210[.]196[.]194.

  • Targeting: This operator focuses heavily on mass-market VPNs, cloud storage, and trending AI tools (DeepSeek, Tencent Yuanbao, Doubao).

Cluster 2:
A second distinct operator utilizes the email 3799492994@qq[.]com and the registrant name "崔勇强" (Cui Yongqiang). This actor registered 113 domains in the post-arrest window.

  • TTPs: Like Cluster 1, this operator provisions dedicated Alibaba Cloud HK IPs (ASN 401696), but groups their infrastructure by specific deployment dates rather than strictly by brand.

  • Targeting: This actor exhibits a highly targeted focus on financial and enterprise platforms. Lures exclusively target users of MetaTrader 4, MetaTrader 5, TradingView, AiCoin, and specialized enterprise customer service applications like WangshangLiao (旺商聊) and KefuBao (客服宝).

Cluster 3:
A third, smaller cluster operates independently from the Alibaba Cloud infrastructure, utilizing a Hong Kong hosting provider named LucidaCloud and the email daliandahouzi@gmail[.]com ("da houzi").

  • Targeting: This operator specifically targets futures trading platforms, utilizing unique lures such as "奇货神器" (Rare Goods Magic Weapon - a futures trading decision platform).

Traffic Redirection and Analytics Tracking

Consistent with findings in Part II, the operators continue to leverage tracking pixels and redirect hubs to manage campaign traffic. Analysis identified the continued use of Google Analytics 4 (GA4) tags (e.g., G-3GR90RW2M5) embedded across crypto-wallet phishing sites (imToken, AiCoin) to monitor victim interaction.

Additionally, the operators utilize centralized redirect hubs. Domains such as osnenfae[.]xyz (impersonating the OpenClaw AI agent) do not host payloads directly. Instead, these domains function as traffic directors, routing victims to central hubs like opencnwl.com[.]cn where the actual payload delivery mechanisms are hosted. This compartmentalization of infrastructure complicates takedown efforts, as defenders must identify and block both the outer redirector ring and the inner payload hosting hubs.

Sample Sites Spoofing Malicious Software:

Fake CyclingClaw sign-in page used as a malware download lureSpoofed ChatGPT interface used as a malware download lure
Spoofed Qwen (Tongyi Qianwen) download page used as a malware lureSpoofed imToken crypto wallet site used as a malware download lure
Spoofed Huorong Security antivirus download page used as a malware lureSpoofed AiCoin crypto analytics download page used as a malware lure
Spoofed AnyDesk remote access download page used as a malware lureFake BestVPN download page used as a malware lure
Spoofed iCIBA (Kingsoft PowerWord) download page used as a malware lureFake Kuaicheng VPN download page used as a malware lure
Fake Hello Translator download page used as a malware lureSpoofed v2rayN tutorial and download site used as a malware lure
Spoofed MetaTrader 5 trading platform download page used as a malware lureSpoofed NordVPN download page used as a malware lure
Second spoofed NordVPN download page variant used as a malware lureSpoofed Doubao AI assistant download page used as a malware lure
Spoofed Surfshark VPN download centre used as a malware lureSpoofed TradingView charting platform download page used as a malware lure
Second spoofed AiCoin page variant used as a malware lureSpoofed V2RayN proxy client download page used as a malware lure

Malware Analysis: Modified Gh0stRAT Delivery

Figure 1: Gh0stRAT Malware Execution Chain


The majority of samples analyzed from this recent cluster point to an obfuscated variant of Gh0stRAT. The infection chain utilizes a multi-stage dropper process involving bloated installers, steganography, and compiler-based obfuscation. For the samples reviewed in this campaign, the technical execution chain, obfuscation methods, and final payload structure are nearly identical regardless of the lures.

Inno Setup Bundles

Validating observations from Part IV, the initial payloads are Inno Setup executables artificially padded to sizes ranging from 117MB to over 147MB. The padding is an anti-analysis technique designed to exceed the file size limits of public sandboxes, and security gateways, which are typically around 100-200 MB and subsequently deter automated analysis.

Extracting the Inno Setup files reveals legitimate, digitally signed application binaries bundled with malicious components. In several of the applications observed, the file bundles contain dozens of legitimate applications that serve no purpose other than to increase the file size and the overall application's legitimacy. The setup script utilizes the hidewizard nowait directive, which presents the user with a standard installation GUI while the malicious loader executes silently in the background.

Following the installation routine, execution passes to a 64-bit loader (e.g., XwLOZ.exe). Code analysis of the loader indicates it is heavily obfuscated utilizing OLLVM (Obfuscator-LLVM) and VMProtect/Themida-style protections to complicate control flow analysis. The loader’s primary function is to map a companion DLL (e.g., GQucUJ.WLs) into memory and execute its various exports.

Figure 2: Code Obfuscation Throughout the Execution Chain

Figure 3: Obfuscated Export Names

Once mapped, the DLL searches the local file system for a specific data file dropped during the initial installation phase (e.g., DsHeEOJ6.bG). All DLLs analyzed share the same obfuscation compiler as the EXE loader component.

Payload Decryption

The DsHeEOJ6.bG file is structured to masquerade as an 800x600 PNG image, utilizing the standard %PNG (47 4e 50 89) magic bytes in its header. The DLL allocates a ~10MB memory segment with Read-Write (RW) permissions, removes the PNG headers, and decrypts the underlying payload. Following decryption, it uses VirtualProtect to modify the memory permissions to Read-Write-Execute (RWE) and redirects execution to the decrypted shellcode.

The decrypted shellcode is based on an sRDI (Reflective DLL Injection) implementation and uses the RtlDecompressBuffer API to unpack an embedded PE file into a new memory region.

Figure 4: sRDI Style Shellcode

The shellcode injects the final unpacked DLL payload as a headless PE into a separate, legitimate system process. In observed instances, the malware targets sihost.exe (Shell Infrastructure Host). By executing exclusively within the context of a trusted system process, the malware blends its subsequent network and file operations with normal operating system behavior. Additionally a lightweight watchdog DLL is injected into a separate system process such as uhssvc.exe (Microsoft Update Health Tools). It is worth noting that the DLL payload uses the same obfuscation compiler as the loader EXE and DLL, but the watchdog DLL does not.

To ensure continuous execution of the injected Gh0stRAT payload, the malware establishes a local watchdog mechanism. It drops a batch file into the C:\Windows\ directory utilizing a randomized 8-character filename (e.g., C:\Windows<random_8_chars>.bat). The contents of this script are obfuscated, but de-obfuscation reveals a continuous monitoring loop utilizing system utilities:

Figure 5: Deobfuscated Batch Script

If the tasklist command returns an error, indicating the injected uhssvc.exe process has been terminated, the batch script issues an sc start command to restart the obfuscated malicious service, effectively functioning as a persistent watchdog for the main Gh0stRAT process.

To facilitate execution within protected system boundaries and establish service-based persistence, the payload first performs a User Account Control (UAC) bypass. It achieves this by abusing the ICMLuaUtil elevated COM interface (CLSID {3E5FC7F9-9A51-4367-9063-A120244FBEC7}). This allows the malware to silently elevate its privileges without prompting the user.

Figure 6: UAC Bypass using ICMLuaUtil COM Interface

Configuration and Capabilities

Prior to initiating network communications, the injected payload reads its configuration from a hardcoded path: C:\ProgramData\C46EEF09DFB549819FACDBF1C9081293\config.ini.

The configuration file is XOR-encrypted using a static 0x62 key. Decryption yields operational parameters, versioning (version=s9C4pg==), and campaign group identifiers (e.g., group=tLa0uLa4tLim).

Figure 7: Decrypted Configuration File

Secondary persistence is established by copying an executable to a randomized path within the C:\msys64\ directory (e.g., C:\msys64\IHGW\qqit\aqzaeX\wKBe\yD4C7.exe). This executable is registered and launched as a service via cmd.exe.

Analysis of the unpacked payload confirms the core capabilities of Gh0stRAT. Extracted API calls show standard GDI and GDI+ functions (GdipCreateBitmapFromHBITMAP, BitBlt, StretchBlt) for screen capture, as well as SetWindowsHookExW and GetAsyncKeyState for keylogging. The payload utilizes WMI queries (ROOT\CIMV2) for system enumeration.

The payload also contains strings indicating targeted data collection and evasion. It queries specific paths for WeChat, Telegram, and regional browsers (e.g., %s\360se6\User Data\Default, NoLogWechat, NoLogTG). Additionally, the code checks for the presence of 360Hvm64.sys, a component of Qihoo 360 security software, indicating specific anti-analysis measures for Chinese operating systems.

Command and Control (C2)

Code analysis reveals class structures such as CTcpPackClientT, IPackClient, and CTcpClient, indicating the use of hp-worker (High-Performance Socket), an IOCP-based C++ networking library. This aligns with past observed behavior of other Gh0stRAT variants, which also utilize updated C++ network libraries to manage asynchronous data streams.

Figure 8: Network Data Stream for Gh0stRAT

Alternative Gh0stRAT Variant:

While the OLLVM/Inno Setup chain is the most prevalent in this cluster, analysis of AiCoin lures (e.g., AIcosin_x64.exe) revealed a distinct, secondary infection chain.

Like the primary variant, the initial installer is padded (~163MB); however, it utilizes an Advanced Installer package rather than Inno Setup. Execution relies on a DLL sideloading against a legitimate dropped executable (e.g., BrowserProtect.exe). The malicious DLL (DataState.dll) is 20MB in size and, notably, is signed with a valid Authenticode certificate issued to a Chinese company ("Shanxi 90s Catering Management Co., Ltd."). The use of a valid, stolen, or otherwise fraudulently obtained certificate allows the payload to bypass initial Mark-of-the-Web (MoTW) and endpoint trust checks.

This alternative chain lacks the compiler-level obfuscation seen in the primary variant. An injected DLL decrypts the final embedded payload, which matches publicly available Gh0stRAT code.

Indicators of Compromise (IoCs)

Inno Setup Installer Cluster

The majority of these samples share a common pattern: 32-bit Inno Setup installers built with a Delphi (XE2–XE6) compiler and Turbo Linker. Each drops 3 embedded files and beacons to 2 C2 addresses (a domain + an IP:port pair).

Obfuscated Gh0stRAT Variant 

Installer Name Installer SHA256 EXE Loader Name EXE Loader SHA256 DLL Name DLL SHA256 Encrypted Payload Name Encrypted Payload SHA256 C2 Domain C2 IP:Port
cnkuai_miao_x64_6lt81.exe51385d63916a23480e38c1db5ec47608f31db3b3c7f1ebb0c5b207565b18a00frzjP0k.exedc98290d491b1a06e5b1e1c50cd70d99ba729545452185cb324c0db8ea6a28f1NBRq69tK.T9l8fbab5008074cf93859c09f82b9214d5acc9e473f1bb04648dee1d83502a73b4Y2JP.0f35ad6e05981aeb7bbfa62837b3d6e35367ba856388e246a8cae8b51fe856f46www[.]uvsryx7i[.]com8[.]210[.]220[.]5:80
cnv2_raynx64_winsisuxe.exe0796130f37db020dc1f3619391c7c750fa4527b84ef2eb7a76c69c467ad80897bL5I.exeb4fd12c8ae54a7c1763d7894b24d4f3f43fde3b661a9cf8ba5c020e539c71cb1GZpPIE4U.ie3ecc8ee0856069bd9f804132a520b249212956f5e8975f805b15abf64632c69v1kxWW.p89fd6e180cae4659dc5e5442a9c71ac979dc0f44179f55b3fd9d1b4846b62dba0www[.]starx8[.]com47[.]238[.]68[.]204:8080
flyfastccpn_x64.exe57f25d75f47ccdcb0a2be98d0fb4d081d9f7893880bf0050d6462c3f652bb2cbXrgV.exef1c28e53fcf534c08dfc534ff147584cb0a2ed0bcfbae91591d005a1878f047bnB.Be9c7ab11b862f26ca4921c5ff7df3549c8a94dc9c52f170941dee5003d3e93545dV0Si6.g0A5166ec466e894a89f69eaee10d04e20c96752f8ae622f01e935c8574697126d5www[.]uvsryx7i[.]com8[.]210[.]220[.]5:80
kuaichenfast_x64winsis.exe8b7d9ec5929f77617dd03cded74de742c98ea0788ebb5b3e2725c741bbb2581b9FAZEI.exef1c28e53fcf534c08dfc534ff147584cb0a2ed0bcfbae91591d005a1878f047bnB.Be9c7ab11b862f26ca4921c5ff7df3549c8a94dc9c52f170941dee5003d3e93545dV0Si6.g0A5166ec466e894a89f69eaee10d04e20c96752f8ae622f01e935c8574697126d5www[.]uvsryx7i[.]com8[.]210[.]220[.]5:80
letsSetup.exeeac7b98e6fbb50b9cf72910897433d500b0e2350561d2463db5014f559146f8da1Ow.exe937f6a7e86733a2b8bacebb357fb3d14c960faf3f10bbfea5627c7735d6318b8f.t0i127c21f10abe1fccd90133b5ba8f83dc1b1de5580bb2dc71ea4329d64e2e7701zwaACq.pc99e8389923751bb1bd7d71ebef3125e41b9366fbae36d87dd723320629cf6a5puppybob[.]xyz45[.]119[.]98[.]169:45
Meta_trader_4.exe9e2a3a468bdf99c3428bd31c29aba4c99e028ca6bdfe2e9f9657a27ff2c5f522KaI5eivaAh.exe595ad8fcecb1bd9e9ece57fbb8428ce031a7b3db06758a3add6432c8086bb1bbsIbHOt.X12dd624b7e0cef5980723fe9da6901ba9b02566624ade4002dbfdcb6cd85b442f0ndxTU.826e9bb278e2da8bf2ae68c9377bf4e4daef2c3bc460bc2067a0a327568b264b9lasjx[.]com154[.]23[.]184[.]235:53
Metatrader5.exeaf257229403128b1a13dc6f45a674382b5faeca693a973c25b3a2d82e44b8260NlixJzDM.exe7b7c25e653ddba1f4aeb0f13ee091b90b2983de70bafc7f1bbb0b7a317a75296AwvxchW0.3c726746595f7ef940ee201bfb9b977d53f404b768c88d44535058f4446da4eddOwzU.H09daf847a00bc5c56ae18f7e5327eff3495981acdb0f663196b1ef2f5af6da72lasjx[.]com154[.]23[.]184[.]235:53
sys_HR_allapp_x64.exe_EANej.exe16f1591190994c0d38e184e57d0d9fca5f004e3eeb80934244c5472861c66692sOeFm.exed424ab3b2f639a7a9a06a623269e2ba8bd2957795031077f13a743dc189dda39Kp0zrJf.KD735eae9d504285dd3d684dc3787af3a1ef83dbbc4200e60a579bb5ba830fa0d8RbHR.nw728c607aac876dafc1df4e487302698a1edfdfb1a01216aae04307306c88cd6ewww[.]yamatofin[.]com47[.]83[.]128[.]111:22
xia0_huojianv2x64.exe1cca336c70e0cbf64bc0805cfc707c956a132ec2e43e24d34ff7126467d7fd2fuIaq8Q.exe2f26cb96f34af9b98e2a360f017930957a9a8f759562562381b00679c21d07aeBk.lR4e87f7cc3dc468b1ea3f9fb872ec3a15f8cef771c04c0465245d79422af2cc05FEOalM.8d7f619f517f42cd09700080169b7a94b1f605fcad3101543ffc1d6fe278aa52awww[.]starx8[.]com47[.]238[.]68[.]204:8080
Aicoin_steup.exed3db6d0f7062b00d4abbcb0471d3c11172389d0154ab977442404487d3746d74NlixJzDM.exe7b7c25e653ddba1f4aeb0f13ee091b90b2983de70bafc7f1bbb0b7a317a75296AwvxchW0.3c726746595f7ef940ee201bfb9b977d53f404b768c88d44535058f4446da4eddOwzU.H09daf847a00bc5c56ae18f7e5327eff3495981acdb0f663196b1ef2f5af6da72lasjx[.]com154[.]23[.]184[.]235:53
pron_tonx64_8Ya4.exea01b2afd5fda05bf5ee2b80fbb460e064c7fab8bb96653545d0415eb8ad6d57eyD4C7.exe2249135811ac7c27caa6aeb87ff7e28df4c367b25b49bb540d57f4fca51d08d5KRNraQxS.lafa71805b8bd83c77f8cc098a64c1203cbf6206072734eee0471bb981bb950e2N5EPR.jf912a1a8ba6ae8390398de79ce081d0f274117346da607aeee3d3cf91cf65c31www[.]yamatofin[.]com47[.]83[.]128[.]111:22
doubao-AI.exee4aec3d3f546aa6c969337202a0899807109924e92587dc4eb597066d0d2ea26XwLOZ.exe (confirmed role)18abba9917d4a8f76fbcb59e049906168126d0fc392ebca512f2715bb9fd2ee0GQucUJ.WLs (confirmed role)fc21639aeee1d6084a0ec6984072cb1e5fb701ba1b92b2bb54b8cc315a78fa7bDsHeEOJ6.bG (confirmed role)029f446d884a7de116bbeb06ef04c1d19137d4a8e6980be77ee53636d8f20b52www[.]mq12ote0[.]com137[.]220[.]158[.]91:8080


Gh0stRAT Variant v2

File Name Type Role SHA256 C2
AIcosin_x64.exeEXEMain installer (spoofed "aicoin" branding)704ba3eb10f04f053f150e7eca60bb90931a7a0af80f571359424ad0929a4dbdabc[.]yu32k1[.]com
6840000.dllDLLGh0stRAT payload injected into the legitimate BrowserProtect process0d44f92753f56ecb313c0271757f1212281d30f0a341a1e55329ce86f8573776(uses parent's C2 channel)
DataState.dllDLLGh0stRAT loadercbe0e7173f3c5265fffe79951f6e456df020fd0add02bb37cd622827e5824ae2(uses parent's C2 channel)


Payload Delivery Domains and Lure Domains are available in the DTI IoC Library on GitHub.

Related Content

Research
Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.

DomainTools Investigations exposes the Zedxion and Zedcex ecosystem—a layered financial architecture leveraging disposable UK shell companies, persistent digital tokens, and UAE-based trade fronts to facilitate IRGC-linked sanctions evasion and illicit Iranian funds transfers.

Learn More
Research
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

Moving beyond traditional state-centric APT structures, the pro-Iran coalition of jihadist-aligned collectives, nationalist actors, and opportunistic groups coordinates via Telegram to turn low-cost cyber operations into high-impact psychological warfare. While individual actors primarily rely on technically unsophisticated tradecraft like DDoS-for-hire tools, website defacements, and recycled breach data, their strategic strength lies in speed, visibility, and rapid mobilization alongside real-world kinetic events.

Learn More
Research
Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

DTI reveals how Russia, China, and Iran are exploiting weak OT security and internet-facing PLCs to target critical water and wastewater infrastructure. From Volt Typhoon's strategic pre-positioning to Sandworm-adjacent sabotage, discover the primary TTPs, vulnerabilities, and MITRE ATT&CK mappings reshaping modern hybrid warfare.

Learn More