HomeSecuritySilver Fox targets Indian users with ValleyRAT malware

Silver Fox targets Indian users with ValleyRAT malware

The malicious actor known as Silver Fox has turned its attention to India, using income tax-themed bait in phishing campaigns to distribute a modular remote access Trojan called ValleyRAT (also known as Winos 4.0).

See also: Hackers distribute ValleyRat via Telegram, WinSCP, Chrome and Teams

Silver Fox ValleyRAT

“ This sophisticated attack leverages a complex chain involving DLL compromise and the modular Valley RAT to ensure persistence ,” said CloudSEK researchers Prajwal Awasthi and Koushik Pal , in an analysis published last week.

Also known as SwimSnake, The Great Thief of Valley (or Valley Thief), UTG-Q-1000 , and Void Arachne, Silver Fox is the name given to an aggressive cybercrime group from China that has been active since 2022.

It has a history of organizing diverse campaigns with motives ranging from espionage and intelligence gathering to financial gain, cryptocurrency mining, and operational disruption, making it one of the few hacking groups with a multi-faceted approach to their hacking activity.

Primarily targeting Chinese-speaking individuals and organizations, Silver Fox's victimology has expanded to include organizations operating in the public, financial, medical, and technology sectors. The group's attacks have leveraged search engine optimization (SEO) poisoning and phishing to distribute Gh0st RAT variants such as ValleyRAT, Gh0stCringe , and HoldingHands RAT (also known as Gh0stBins).

See also: Silver Fox leverages Microsoft WatchDog to develop ValleyRAT

Silver Fox targets Indian users with ValleyRAT malware

In the infection chain documented by CloudSEK, phishing emails containing deceptive PDFs purporting to come from the Income Tax Department of India are used to deploy ValleyRAT. Specifically, opening the PDF attachment takes the recipient to the “ggwk[.]cc” domain, where a ZIP file (“tax affairs.zip”) is downloaded.

Inside the file is a Nullsoft Scriptable Install system (NSIS) installer with the same name (“tax affairs.exe”), which, in turn, leverages a legitimate executable file associated with Thunder (“thunder.exe”), a Windows download manager developed by Xunlei, and a malicious DLL (“libexpat.dll”) loaded from the binary.

The DLL disables the Windows Update service and acts as a conduit for a Donut loader, performing various anti-parsing checks to ensure that the malware can run unhindered on the compromised computer. The loader then injects the final ValleyRAT payload into an empty “explorer.exe” process.

ValleyRAT is designed to communicate with an external server and await further commands. It implements a plugin-oriented architecture to extend its functionality in an ad hoc manner, allowing its operators to deploy specialized capabilities to facilitate keylogging, credential harvesting, and defense evasion.

See also: Silver Fox Group Targets Companies in Taiwan

Silver Fox targets Indian users with ValleyRAT malware

The fake websites created by Silver Fox have been found to mimic CloudChat, FlyVPN, Microsoft Teams, OpenVPN, QieQie, Santiao, Signal, Sigua, Snipaste, Sogou, Telegram, ToDesk, WPS Office, and Youdao, among others. An analysis of the source IP addresses that clicked on the download links has revealed that at least 217 clicks originated from China, followed by the U.S. (39), Hong Kong (29), Taiwan (11), and Australia (7).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS