Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign
Silver Fox APT is executing targeted attacks in Taiwan, utilizing DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to deploy Winos 4.0 (ValleyRat) while disabling security tools.
Silver Fox APT is executing targeted attacks in Taiwan, utilizing DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to deploy Winos 4.0 (ValleyRat) while disabling security tools.
The campaigns employ localized tax and e-invoice lures and rapidly changing infrastructure, making them difficult to block with static indicators. Emails and download pages imitate official tax audit notices, e-invoice portals, and tax filing installers, deceiving users into accessing weaponized archives or links.
In one campaign, victims receive a RAR archive named "taxIs_RX3001.rar," which includes a benign decoy document and a malicious LNK shortcut. The LNK uses a relative path to launch cmd.exe and executes a series of commands that establish a working directory under %Public%\501, impersonate curl.exe as url.exe, and download a payload named Setup64.exe from attacker-controlled infrastructure.
The downloaded installer, presented as a 64-bit "special edition" package, extracts an embedded executable resource into C:\ProgramData\Golden, forming the base for the deployment of Winos 4.0 and its driver component.
A subsequent campaign shifts from LNK-based downloaders to DLL sideloading via legitimate Taiwanese applications distributed in tax- or e-invoice-themed archives. Phishing links and fake e-invoice URLs redirect victims to China-hosted cloud storage, where archives contain both a trusted executable and a malicious DLL. When the user runs the legitimate-looking application, it sideloads the attacker’s DLL, deploying the same driver-based evasion and Winos 4.0 backdoor used in the initial campaign.
The campaigns employ localized tax and e-invoice lures and rapidly changing infrastructure, making them difficult to block with static indicators.
The DLL's PDB path reveals an internal project name, and related samples reference another tax application used for sideloading, with the C2 shifting to a new IP address. Domain registration data for these operations shows patterns in registrant identity and reuse of the same Winos 4.0 C2, reinforcing attribution to a focused Silver Fox subgroup.
The payload, Winos 4.0 (or ValleyRat), is a Gh0st-derived remote access trojan associated with Silver Fox operations. It checks for administrative rights and uses a UAC bypass if necessary, launching a BYOVD sequence to load a vulnerable, signed kernel driver. This driver enables low-privileged code to disable security processes, ensuring a clean environment for persistence and remote control.
C2, Plugin Architecture, and Attribution
Winos 4.0 conceals its C2 address using Base64-encoded configuration data, connecting only after verifying the system version. Once online, it retrieves a DLL and additional plugins for file management, screen capture, and system management, some stored directly in the registry for fileless execution.
Infrastructure links, reuse of codebase, and driver abuse align with prior Silver Fox APT activity targeting Taiwan and other regions. This campaign highlights the need for monitoring DLL sideloading behavior, blocking vulnerable drivers, and treating unsolicited tax- or invoice-related files as high-risk.
47[.]76[.]86[.]151 - Likely hosting malicious payloads or redirect domains
bqdrzbyq[.]cn - Suspicious Chinese domain taxfnat[.]tw - Taiwan-based phishing-style naming njhwuyklw[.]com - Likely random-generated twtaxgo[.]cn - Used in malicious URL taxhub[.]tw - Impersonates tax-related service taukeny[.]com - Randomized domain structure taxpro[.]tw - Taiwanese tax-themed naming lmaxjuyh[.]cn - Possible command-and-control domain tkooyvff[.]cn - Suspicious structure etaxtw[.]cn - Mimics legitimate Taiwanese tax system twswsb[.]cn - Obfuscated hostname
Based on reporting by GBHackers.
