Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign

Silver Fox APT is executing targeted attacks in Taiwan, utilizing DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to deploy Winos 4.0 (ValleyRat) while disabling security tools.

Silver Fox APT is executing targeted attacks in Taiwan, utilizing DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to deploy Winos 4.0 (ValleyRat) while disabling security tools.

The campaigns employ localized tax and e-invoice lures and rapidly changing infrastructure, making them difficult to block with static indicators. Emails and download pages imitate official tax audit notices, e-invoice portals, and tax filing installers, deceiving users into accessing weaponized archives or links.

In one campaign, victims receive a RAR archive named "taxIs_RX3001.rar," which includes a benign decoy document and a malicious LNK shortcut. The LNK uses a relative path to launch cmd.exe and executes a series of commands that establish a working directory under %Public%\501, impersonate curl.exe as url.exe, and download a payload named Setup64.exe from attacker-controlled infrastructure.

The downloaded installer, presented as a 64-bit "special edition" package, extracts an embedded executable resource into C:\ProgramData\Golden, forming the base for the deployment of Winos 4.0 and its driver component.

A subsequent campaign shifts from LNK-based downloaders to DLL sideloading via legitimate Taiwanese applications distributed in tax- or e-invoice-themed archives. Phishing links and fake e-invoice URLs redirect victims to China-hosted cloud storage, where archives contain both a trusted executable and a malicious DLL. When the user runs the legitimate-looking application, it sideloads the attacker’s DLL, deploying the same driver-based evasion and Winos 4.0 backdoor used in the initial campaign.

The campaigns employ localized tax and e-invoice lures and rapidly changing infrastructure, making them difficult to block with static indicators.
Rachel Green · Thehackingpost

The DLL's PDB path reveals an internal project name, and related samples reference another tax application used for sideloading, with the C2 shifting to a new IP address. Domain registration data for these operations shows patterns in registrant identity and reuse of the same Winos 4.0 C2, reinforcing attribution to a focused Silver Fox subgroup.

The payload, Winos 4.0 (or ValleyRat), is a Gh0st-derived remote access trojan associated with Silver Fox operations. It checks for administrative rights and uses a UAC bypass if necessary, launching a BYOVD sequence to load a vulnerable, signed kernel driver. This driver enables low-privileged code to disable security processes, ensuring a clean environment for persistence and remote control.

C2, Plugin Architecture, and Attribution

Winos 4.0 conceals its C2 address using Base64-encoded configuration data, connecting only after verifying the system version. Once online, it retrieves a DLL and additional plugins for file management, screen capture, and system management, some stored directly in the registry for fileless execution.

Infrastructure links, reuse of codebase, and driver abuse align with prior Silver Fox APT activity targeting Taiwan and other regions. This campaign highlights the need for monitoring DLL sideloading behavior, blocking vulnerable drivers, and treating unsolicited tax- or invoice-related files as high-risk.

Advertisement

47[.]76[.]86[.]151 - Likely hosting malicious payloads or redirect domains

bqdrzbyq[.]cn - Suspicious Chinese domain taxfnat[.]tw - Taiwan-based phishing-style naming njhwuyklw[.]com - Likely random-generated twtaxgo[.]cn - Used in malicious URL taxhub[.]tw - Impersonates tax-related service taukeny[.]com - Randomized domain structure taxpro[.]tw - Taiwanese tax-themed naming lmaxjuyh[.]cn - Possible command-and-control domain tkooyvff[.]cn - Suspicious structure etaxtw[.]cn - Mimics legitimate Taiwanese tax system twswsb[.]cn - Obfuscated hostname

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories