Executive Summary
The SilverFox threat actor has significantly evolved its delivery infrastructure, transitioning through four distinct stages: unconditional delivery, Referer-based whitelisting, and finally a sophisticated cloud-based 'blacklist' mechanism. This latest evolution, observed in September 2026, involves a three-tier architecture (Phishing Site -> Relay/Dispatcher -> Payload Host) designed to filter out security analysts by serving harmless content, such as legitimate WeChat installers, to suspected researchers while delivering actual malware to targeted victims.
Technical analysis reveals that SilverFox uses SEO poisoning to lure users to highly convincing clones of popular software sites (e.g., SteelSeries GG, Bcut). The delivery decision is made at a centralized relay tier (api.php) hosted on Cloudflare, which evaluates the 'Referer' header. Domains flagged as 'exposed' are moved to a blacklist, causing the dispatcher to return non-malicious links, effectively neutralizing the phishing site without taking it offline, thereby preserving operational telemetry through 51.LA statistics scripts.
This shift highlights the group's ability to adapt tradecraft in response to researcher activity. The use of redundant Cloudflare Workers and hidden download triggers (iframes and 'no-referrer' anchors) indicates a high level of engineering maturity focused on infrastructure longevity and defense evasion.
