Skip to content
skopnix
← adversaries
Unknown

Void Arachne

Silver Fox
misp-galaxyrefreshed 2026-09-15

sigil

Last 30 days

last seen 16 d ago

2
dispatches
0
victims
0
CVEs seen
Analyst brief

Void Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers for AI software. They exploit public interest in VPN technology and AI software to distribute malware through SEO poisoning and Chinese-language-themed Telegram channels. The group's campaign includes bundling malicious Winos payloads with deepfake pornography-generating AI software and voice-and-face-swapping AI software. Void Arachne also promotes AI technologies for virtual kidnapping and uses AI voice-alternating technology to pressure victims into paying ransom.

Take it with you
References
Early access

Track Void Arachne on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected