logo

Stealth Injection: Silver Fox APT Upgrades “ValleyRat” with Rare PoolParty Tech

ID: 42aa4ba4-810d-5f79-a332-1f65b7c7d4dd

STIX ID: report--42aa4ba4-810d-5f79-a332-1f65b7c7d4dd

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Cybereason reports a campaign distributing ValleyRat (Winos 4.0) via fake installers targeting Chinese-speaking users; the malware uses an uncommon "PoolParty Variant 7" I/O completion port process-injection (duplicating Explorer.exe handles and calling ZwSetIoCompletion) to execute stealthily, implements an injected watchdog for resilient persistence (into Explorer.exe and UserAccountBroker.exe), and actively interferes with Chinese security products (e.g., Qihoo 360 processes). The activity is linked to the Silver Fox APT and shares tradecraft similarities with SADBRIDGE, and users are advised to verify digital signatures and certificates carefully.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.