Silver Fox Exploits Trusted Applications for Malware Distribution
In a recent revelation by The Hacker News, the cyber threat group known as Silver Fox has been found to distribute the ValleyRAT backdoor, cleverly disguised as a legitimate signed Chinese adware application. This tactic enables the malware to operate within a trusted process, posing a significant risk to users who may inadvertently include such software in their antivirus exclusions, as highlighted by Kaspersky.
The ValleyRAT, also referred to as Winos 4.0, has been bundled with QN Wallpaper, a genuine desktop wallpaper tool from China. Upon installation, ValleyRAT bestows the attacker with comprehensive control over the infected machine, allowing for the collection of sensitive information, the capture of screenshots, and the deployment of additional malicious modules.
This sophisticated attack employs a technique known as DLL sideloading. In this process, a modified version of QN Wallpaper is unpacked, and its signed executable subsequently loads a malicious DLL that has been strategically placed in the same directory. This method enables the backdoor to execute within a trusted process, effectively circumventing signature-based security measures.
Before the adware component becomes active, the installer takes proactive steps by disabling Windows Defender and adding itself to the autorun entries. In instances where the logged-in user does not possess administrator rights, the malware cleverly utilizes the “runas” command to elevate its privileges. Furthermore, ValleyRAT marks its process as critical, which can trigger a blue screen of death if any attempts are made to terminate it.
Kaspersky’s in-depth analysis has pointed to Silver Fox as the likely architect behind this campaign, a group that has previously demonstrated a penchant for employing similar DLL sideloading techniques in their operations.