Silver Fox Campaign Spreads ValleyRAT via Fake Chinese Telegram Language Pack
ID: 752e6f89-7405-5f90-a870-5d97113dcaa8
STIX ID: report--752e6f89-7405-5f90-a870-5d97113dcaa8
Feed Name: GBHackers
This report analyzes a Silver Fox campaign that distributes ValleyRAT and a BYOVD kernel rootkit through a trojanized Telegram Chinese language pack MSI; the installer uses VBScript/PowerShell to XOR-decrypt ZPAQ archives (unpacked with a signed zpaqfranz LOLBin), conditionally sideloads malicious DLLs via a ByteDance-signed elevation service, and abuses the wnBios driver for kernel memory access. The write-up includes a six-stage infection chain, indicators such as C2 118.107.43.65 and filenames (e.g., DesignAccent.exe, SingMusice.exe), TTPs for evasion and persistence, and mitigation guidance to block the CTG Server netblock and hunt for the listed artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
