TA4922
Also known as Silver Fox, Void Arachne
Reports
5
First seen
Jun 3, 2026
Last seen
Jul 27, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1566 Phishing ×5T1219 Remote Access Software ×3T1056 Input Capture ×2T1027 Obfuscated Files or Information ×2T1041 Exfiltration Over C2 Channel ×2T1105 Ingress Tool Transfer ×2T1218 System Binary Proxy Execution ×2T1005 Data from Local System ×2T1555 Credentials from Password Stores ×1T1571 Non-Standard Port ×1T1003 OS Credential Dumping ×1T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder ×1
Indicators
cve ×51filename ×2domain ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High