Void Arachne (Silver Fox APT) Targets Taiwanese Government & Tech Firms in Spear-Phishing-Driven Espionage Campaign

Sophie Zhu
February 27, 2025
Void Arachne, also known as Silver Fox APT, is a China-linked espionage group targeting Taiwanese government agencies, technology firms, and critical sectors through spear-phishing emails carrying RATs such as ValleyRAT and Gh0st derivatives. Their focus is on intellectual property theft and maintaining long-term covert access.
In June 2025, Intel 471 reported a targeted cyberespionage campaign against government and technology organizations in Taiwan, conducted by an advanced persistent threat actor known as Void Arachne (Silver Fox APT). This attack focused on stealing intellectual property and sensitive organizational data using sophisticated email-based infiltration methods
The campaign worked through the deployment of carefully crafted spear-phishing emails containing malicious attachments. Once the recipient opened these attachments, the attackers gained an initial foothold, leveraging remote access trojans (RATs) such as Gh0stCringe and HoldingHands. These RATs enabled persistent remote access, allowed for exfiltration of confidential documents, and incorporated stealth techniques designed to evade traditional endpoint detection tools. Silver Fox further strengthened their attacks using signal-based and multi-channel methods to reduce the risk of interception.
This operation highlights how cyberespionage is escalating in strategically important regions like Taiwan, a global technology hub. Void Arachne's (Silver Fox APT) use of custom-built RATs and multi-platform communication channels demonstrates increasing sophistication among threat actors. The campaign underscores a growing need for organizations to invest in advanced phishing detection and improved security for enterprise messaging platforms to defend against evolving attack methods.

To defend against threats similar to those used by Void Arachne (Silver Fox APT) targeting government and technology organizations:

  • Advanced Phishing Detection
    Deploy anti-phishing solutions capable of analyzing attachments and embedded payloads in real time.
  • Endpoint EDR Coverage
    Detect RAT activity and unauthorized remote control tools across all endpoints, including off-network devices.
  • Messaging Platform Security
    Secure enterprise messaging platforms against malicious file transfers and phishing links.
  • Access Review
    Conduct regular audits of privileged accounts and third-party integrations for signs of abuse.

ITDR detects anomalous user behavior and compromised accounts in SaaS environments. Browser Extension Protection blocks phishing sites and prevents session hijacking.

Void Arachne (Silver Fox APT)’s recent campaign underscores the need for layered security and SaaS-native threat detection. Organizations should combine user education, identity threat protection, and SaaS configuration hardening to minimize risk. Obsidian’s continuous monitoring and context-aware alerts help defenders identify and respond to threats before damage is done.