logo

Silver Fox Campaign Spreads ValleyRAT via Fake Chinese Telegram Language Pack

ID: 752e6f89-7405-5f90-a870-5d97113dcaa8

STIX ID: report--752e6f89-7405-5f90-a870-5d97113dcaa8

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report analyzes a Silver Fox campaign that distributes ValleyRAT and a BYOVD kernel rootkit through a trojanized Telegram Chinese language pack MSI; the installer uses VBScript/PowerShell to XOR-decrypt ZPAQ archives (unpacked with a signed zpaqfranz LOLBin), conditionally sideloads malicious DLLs via a ByteDance-signed elevation service, and abuses the wnBios driver for kernel memory access. The write-up includes a six-stage infection chain, indicators such as C2 118.107.43.65 and filenames (e.g., DesignAccent.exe, SingMusice.exe), TTPs for evasion and persistence, and mitigation guidance to block the CTG Server netblock and hunt for the listed artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.