logo

Silver Fox’s Russian Ruse: ValleyRAT Hits China via Fake Microsoft Teams Attack

ID: 0e7668ad-60f8-5da8-88b7-fdf704a07d14

STIX ID: report--0e7668ad-60f8-5da8-88b7-fdf704a07d14

Feed Name: ReliaQuest Blog

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-29

...
...

Executive summary: ReliaQuest reports a high-confidence attribution to the Chinese APT 'Silver Fox' for an active SEO-poisoning campaign impersonating Microsoft Teams that delivers an updated ValleyRAT loader to Chinese-speaking users and organizations with operations in China; the report describes the ZIP/Setup.exe infection chain, use of Cyrillic false flags, binary-proxy DLL execution via rundll32, PowerShell-based Defender exclusion modifications, related infrastructure and IOCs, and recommends enhanced logging, EDR, and defensive playbooks to detect and contain infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.