DICOM Viewers Impersonated in Malware Distribution Campaign

A China-based threat group is conducting a malware distribution campaign using malicious installers disguised as DICOM viewers. Specifically, the threat group has been observed disguising a malware loader as an installer for Philips DICOM viewers, in an apparent attempt to install malware on the devices of patients and healthcare providers.

DICOM viewers are software applications for viewing medical images stored in the DICOM format. The software is used by medical professionals for viewing DICOM images but also by patients. There are many free-to-use DICOM viewers, although in this case, the installer will deliver a loader that allows other malicious payloads to be downloaded and executed. In this campaign, a second-stage payload is delivered that disables antivirus processes and delivers a third-stage payload of ValleyRAT, a remote access trojan that gives the threat actor access to the user’s device. In this campaign, a ValleyRAT infection leads to the delivery of a keylogger and crypto miner.

The campaign was identified by researchers at Forescout and was attributed to a relatively new China-based threat group known as Silver Fox, aka Void Arachne and The Great Thief of the Valley. The group was first identified in June 2024 and has been highly active since, evolving its tactics and the tools used in its attacks. The first campaigns attributed to the group were on Chinese-speaking targets, although attacks have broadened to include a greater range of targets. In 2024, Silver Fox started targeting companies in finance, sales, accounting, and management enterprises, with its attacks focused on data theft. In contrast to many cyber threat groups, the group is not known to engage in extortion, such as demanding payment to prevent the publication of stolen data.

While Silver Fox could be a financially motivated cyber actor, Forescout suggests Silver Fox could be an Advanced Persistent Threat Group acting under the direction of the Chinese government and that it could only be masquerading as a financially motivated threat actor. The researchers note that the group is focused on data theft, potentially for cyber espionage purposes, and the group’s targets have shifted to government organizations and cybersecurity companies which could suggest a possible China nexus, although links to the Chinese government have not been confirmed.

It is also unclear to what extent healthcare providers and patients are being targeted. In addition to spreading the ValleyRAT through installers masquerading as Philips DICOM viewers, Silver Fox has delivered its malware via installers masquerading as EmEditor, a Windows text editor, and through system drivers and utilities. The creation of malicious Philips DICOM viewers could be part of a broader campaign to infect as many devices as possible. Forescout reports that there are no indications that legitimate Philips devices have been hacked, and the methods used for getting the malicious installers in front of users have not been determined. Since Silver Fox has used SEO poisoning, phishing, and watering holes in the past to distribute its malware, it is likely that similar tactics are being used in this campaign.

As for steps that should be taken to reduce risk, the researchers recommend not downloading software from illegitimate sources, installing endpoint security software on all devices, implementing strict network segmentation to limit the potential for data theft, and monitoring network traffic and endpoint telemetry for suspicious activity.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/