logo

SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign

ID: f9338246-f3e8-53fd-aab2-8bf6cc48ca74

STIX ID: report--f9338246-f3e8-53fd-aab2-8bf6cc48ca74

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Pierluigi Paganini

...
...

SilverFox conducted a targeted campaign against a Japanese manufacturer using invoice phishing and DLL sideloading (via ConvertToPDF.exe and PDFDirect.exe) to load a malicious PDFCORE8.dll that embeds kernel drivers (BootRepair.sys, EnPortv.sys, wsftprm.sys) and deploys ValleyRAT. The malware kills security processes from kernel space, unhooks NTDLL, stores payload/config in the registry (HKCU\Console\0 and HKLM\SOFTWARE\IpDates_sun), performs thread-context injection into svchost.exe, and implements a dual recovery/watchdog persistence mechanism; a C2 IP observed was 43.128.26.132.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.