New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer
ID: 8fd42843-1422-54b1-b91b-0a170d31f963
STIX ID: report--8fd42843-1422-54b1-b91b-0a170d31f963
Feed Name: cybersecurityNews.com
A newly discovered campaign attributed to the Silver Fox group uses a malicious MSI disguised as a Telegram Chinese language pack to install ValleyRAT via a six-stage infection chain that includes a signed LOB binary (zpaqfranz) for unpacking, DLL sideloading or direct execution depending on detected AV, a scheduled-task secondary binary (DesignAccent.exe), and a wnBios kernel rootkit loaded via a Bring-Your-Own-Vulnerable-Driver technique; the ValleyRAT payload contacts C2 118.107.43.65:5040 (netblock 118.107.40.0/21). The report provides IOCs (filenames, PDB signatures, C2 IP/netblock, scheduled task names, zpaqfranz use, MSI custom action behavior), recommends blocking the C2/netblock, alerting on suspicious MSI/VBScript/PowerShell custom actions, flagging zpaqfranz on workstations, and monitoring for the wnBios driver and non-standard AppShellElevationService registrations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
