Thor vs. Silver Fox – Uncovering and Defeating a Sophisticated ValleyRat Campaign
ID: 4a6acba7-9b97-5801-b2b4-0e499090c5ca
STIX ID: report--4a6acba7-9b97-5801-b2b4-0e499090c5ca
Feed Name: Nextron Systems
**Executive Summary:** This report analyzes a sophisticated, active multi-stage malware campaign attributed to the China-aligned APT 'Silver Fox' that distributes trojanized installers (e.g., Telegram) to stage payloads, disable Microsoft Defender, deploy user-writable kernel drivers (BYOVD), perform UAC bypass and DLL sideloading, and ultimately install a persistent ValleyRat beacon; the report includes detailed TTPs, file and network IOCs, and concrete detection and hunting guidance (Sigma/Sysmon examples).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
