A malicious installer disguised as adware delivers the ValleyRAT backdoor through DLL sideloading via a modified libcef.dll loaded by the signed QnWallpaper.exe process. The malware disables Windows Defender via registry modification, employs multiple process protection mechanisms including marking the process as critical to trigger BSOD on termination, and performs spyware activities including keylogging and clipboard capture. The campaign is attributed to the Silver Fox group and has primarily affected users in China and India.
ValleyRAT
4 posts
ValleyRAT masquerading as adware An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails LevelBlue GSOC has identified accelerating ValleyRAT campaigns delivered through fake installers and malicious emails targeting Chinese and Japanese-speaking users. The email-based attack chain uses DLL sideloading via a legitimate VLC executable to load a malicious DLL that downloads an RC4-encrypted, Donut-generated ValleyRAT payload, which is then injected into a suspended rundll32.exe process for fileless execution. The malware incorporates extensive anti-analysis checks (memory size, sleep timing, CPU count, VHD boot detection) and establishes persistence via registry Run keys.
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India The Silver Fox threat group is conducting a phishing campaign targeting organizations in Russia and India with tax-themed lures. The attack chain utilizes a modified RustSL loader featuring geofencing and Phantom Persistence to deploy ValleyRAT. ValleyRAT subsequently downloads a novel Python-based backdoor called ABCDoor, which masquerades as a Tailscale VPN client and provides remote control and screen broadcasting capabilities.
Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware Silver Fox (also known as Void Arachne) is a China-based threat actor conducting dual-purpose campaigns in South Asia that blend financial cybercrime with APT-style espionage. Recent operations leverage tax-themed phishing to deliver evolving payloads, transitioning from the ValleyRAT backdoor to abused legitimate RMM tools, and most recently, a custom Python-based stealer disguised as a WhatsApp application.