Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits
Silver Fox APT Tax-Themed Phishing Campaigns Deploying (TL-2026-0276), also tracked as Operation Silver Fox, is a high-severity advanced persistent threat campaign, first published 2026-03-24. It is attributed to Void Arachne (China) with high confidence, affects Microsoft Windows, maps to 29 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-0276
- Threat ID
- TL-2026-0276
- Also known as
- Operation Silver Fox, Void Arachne Campaign, ValleyRAT Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-24
- Last reviewed
- 2026-03-24
- Attribution
- Void Arachne
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government, financial-services, healthcare, corporate, e-commerce, technology
- Target regions
- Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, Philippines
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in Silver Fox APT Tax-Themed Phishing Campaigns Deploying
Malware and tooling: BlackMoon, CleverSoar, HoldingHands, Nidhogg, ValleyRAT
Silver Fox (Void Arachne), a China-based intrusion set active since 2022, conducts dual APT-espionage and cybercrime operations across the Asia-Pacific region. The group deploys ValleyRAT (Winos 4.0) via tax-themed phishing and SEO poisoning, abuses the Microsoft-signed WatchDog driver (amsdk.sys) for BYOVD privilege escalation and EDR termination, and leverages the Nidhogg kernel-mode rootkit for deep persistence and defense evasion.
How Silver Fox APT Tax-Themed Phishing Campaigns Deploying works
Silver Fox, also tracked as Void Arachne, SwimSnake, The Great Thief of Valley, and UTG-Q-1000, is a sophisticated China-based advanced persistent threat group that has evolved from financially motivated cybercrime to a dual-track operational model combining state-aligned espionage with criminal profit generation. Active since at least the second half of 2022, the group has conducted sustained campaigns targeting Chinese-speaking populations and organizations across Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, and the Philippines.
The group's primary payload is ValleyRAT, a modular C++ remote access trojan also known as Winos 4.0, which operates through a multi-stage infection chain. Initial access is achieved through tax-themed phishing emails impersonating national taxation authorities (particularly Taiwan's National Taxation Bureau), with malicious PDF or ZIP attachments containing DLL files. The group also employs SEO poisoning to distribute trojanized versions of legitimate software including Google Chrome, Microsoft Teams, Telegram, DeepSeek AI, and WPS Office.
ValleyRAT's infection chain involves multiple stages: (1) an initial loader with anti-VM, anti-sandbox, and hypervisor detection capabilities, (2) a beaconing module that performs privilege escalation via CMSTPLUA COM class abuse and fodhelper.exe UAC bypass, (3) a RuntimeBroker persistence component that manipulates the HKEY_CURRENT_USER\Software\Classes\mscfile\Shell\Open\Command registry key, (4) shellcode injection into svchost.exe for defense evasion, and (5) the final ValleyRAT payload with 16+ command capabilities including screen monitoring, keystroke logging, clipboard manipulation, USB device monitoring, and arbitrary shellcode execution.
A defining characteristic of Silver Fox's operations is their Bring Your Own Vulnerable Driver (BYOVD) campaign, first detected by Check Point Research in May 2025. The group exploits a previously unknown vulnerability in the WatchDog Antimalware driver (amsdk.sys, version 1.0.600), built on the Zemana Anti-Malware SDK. Despite being Microsoft-signed with a valid certificate, the driver lacks the FILE_DEVICE_SECURE_OPEN flag and fails to verify Protected Process Light (PPL) status, enabling arbitrary process termination of 192 hardcoded security products including 360 Safe, Kingsoft Antivirus, Tencent QQ PCMgr, and Kaspersky. When targeting Windows 7 systems, the group falls back to the known vulnerable Zemana driver (zam.exe). Notably, after the vendor released a patched driver (wamsdk.sys v1.1.100), Silver Fox attackers bypassed the patch by flipping a single byte in the RFC 3161 timestamp field, preserving the valid Microsoft signature while changing the file hash to evade blocklists.
The group's toolkit extends beyond ValleyRAT to include HoldingHands RAT (a Gh0st RAT variant deployed for premium espionage operations with 60-second heartbeat intervals and dynamic C2 updates), CleverSoar (an MSI-based installer that checks for Chinese/Vietnamese language settings before proceeding), the open-source Nidhogg kernel-mode rootkit (providing process hiding, file protection, registry concealment, AMSI bypass, ETW patching, and PP/PPL signature modification), and Blackmoon (financially motivated malware from the Chinese cybercrime ecosystem). A Python-based stealer impersonating WhatsApp was observed in 2026 campaigns.
C2 infrastructure is hosted across multiple providers including Alibaba Cloud, CTG Server LTD, and Chinese hosting providers. Communication employs HTTP File Server (HFS) for ValleyRAT delivery and TCP-based encrypted channels for Winos 4.0, with XOR encryption (keys including 0x60 and 0x36) and AES-256 for shellcode protection.
MITRE ATT&CK techniques used in TL-2026-0276
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data
defense-evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
discovery
T1057 Process Discovery; T1082 System Information Discovery
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
impact
persistence
T1547 Boot or Logon Autostart Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
initial-access
stealth
resource-development
Affected products and versions in Silver Fox APT Tax-Themed Phishing Campaigns Deploying
- Microsoft — Windows
Vulnerable versions: Windows 7; Windows 10; Windows 11 (up to 25H2) - WatchDog Development — WatchDog Antimalware Driver (amsdk.sys)
Vulnerable versions: 1.0.600
Fixed in: 1.1.100 (partial) - Philips — DICOM Viewers
Vulnerable versions: Multiple versions (trojanized copies) - Multiple — Chinese Antivirus Products (360 Safe, Kingsoft, Tencent QQ PCMgr)
Vulnerable versions: All current versions targeted for termination
Remediation for Silver Fox APT Tax-Themed Phishing Campaigns Deploying
Patches
- Update WatchDog Antimalware driver to latest version (note: v1.1.100 patch is incomplete)
- Apply Microsoft Vulnerable Driver Blocklist updates when amsdk.sys is added
- Ensure all endpoint protection products are updated to detect ValleyRAT variants
Immediate actions
- Block all identified C2 IPs and domains at perimeter firewalls and DNS sinkholes
- Hunt for amsdk.sys and wamsdk.sys driver artifacts on endpoints
- Search for service names Termaintor and Amsdk_Service in Windows service registry
- Monitor for rundll32.exe loading unsigned or unusual DLLs from AppData directories
- Block known malicious file hashes at EDR and email gateway
Workarounds
- Block amsdk.sys and wamsdk.sys driver loading via Windows driver blocklist policies
- Restrict DeviceIoControl API calls from non-privileged processes
- Monitor for Chinese/Vietnamese language checks in installer behaviors as CleverSoar indicator
- Block Alibaba Cloud OSS and Youdao Cloud Notes domains if not business-required
Longer-term hardening
- Deploy Windows Defender Application Control (WDAC) with driver blocklist including amsdk.sys hashes
- Implement strict driver loading policies preventing unsigned or vulnerable kernel drivers
- Enable PowerShell Script Block Logging (Event ID 4104) and Process Creation Auditing (Event ID 4688)
- Deploy behavioral EDR detection for BYOVD patterns including DeviceIoControl abuse
- Establish employee software catalogs to reduce SEO poisoning risk
- Implement network segmentation to limit lateral movement from compromised endpoints
Weaknesses (CWE) in Silver Fox APT Tax-Themed Phishing Campaigns Deploying
CWE-269, CWE-863
Timeline of Silver Fox APT Tax-Themed Phishing Campaigns Deploying
- Silver Fox APT first observed active, initially conducting financially motivated cybercrime operations targeting Chinese-speaking users
- Silver Fox standardizes infection chains and begins systematic deployment of ValleyRAT (early variants) as primary RAT payload
- Philips DICOM viewer trojanization campaign begins; 29 malicious samples identified between July 2024 and January 2025 targeting healthcare organizations
- Rapid7 Labs identifies CleverSoar, a highly evasive MSI installer targeting Chinese and Vietnamese-speaking victims, deploying Winos 4.0 and Nidhogg rootkit
- Taiwan-focused tax authority phishing campaign begins with emails impersonating National Taxation Bureau; PNGPlug loader first identified as part of group TTPs
- Silver Fox APT Winos 4.0 campaign targeting Taiwanese organizations reported, using phishing emails with ZIP attachments containing malicious DLLs communicating with C2 at 206.238.221.60
- Forescout publishes analysis of Silver Fox targeting healthcare sector with trojanized Philips DICOM viewers deploying ValleyRAT backdoors
- ValleyRAT builder leaked publicly, enabling broader adoption; group continues operations with custom variants despite leak
- Check Point Research discovers Silver Fox BYOVD campaign exploiting previously unknown vulnerability in Microsoft-signed WatchDog Antimalware driver (amsdk.sys v1.0.600)
- BYOVD campaign loader sample compiled (SHA256: fc97ad46...), featuring anti-VM, anti-sandbox detection and dual-driver strategy for Windows 7 vs Windows 10/11
- Nidhogg kernel-mode rootkit deployment integrated into Silver Fox operations, providing process hiding, AMSI bypass, ETW patching, and PP/PPL signature modification
- Check Point Research publishes detailed analysis of Silver Fox BYOVD campaign; WatchDog vendor releases partial patch (wamsdk.sys v1.1.100)
- HoldingHands RAT (Gh0st RAT variant) deployment begins for premium espionage operations; campaign expands to Japan and Malaysia
- ReliaQuest reports Silver Fox fake Microsoft Teams campaign with Cyrillic false flags, distributing ValleyRAT via typosquatting domains (teamscn.com, teamszv.com)
- Sekoia TDR publishes comprehensive analysis of Silver Fox tax-themed phishing campaigns spanning 2024-2026 across APAC, documenting evolved TTPs and dual APT/cybercrime model
- As of 2026-05-29, Silver Fox/Void Arachne remains highly active with no takedown or arrests; Kaspersky/Securelist (May 2026) and The Hacker News documented fresh tax-themed campaigns deploying ValleyRAT plus the new ABCDoor backdoor and AtlasCross RAT into India and Russia. Its BYOVD amsdk.sys abuse persists (vendor patch bypassed via timestamp byte-flip) and tooling keeps evolving, confirming a live threat.
Sources cited for Silver Fox APT Tax-Themed Phishing Campaigns Deploying
- Sekoia TDR: Silver Fox Tax Audit Campaign Analysis
- Check Point Research: Chasing the Silver Fox - Cat & Mouse in Kernel Shadows
- Fortinet FortiGuard Labs: ValleyRAT Campaign Targeting Chinese Speakers
- ReliaQuest: Silver Fox Russian Ruse - Fake Microsoft Teams Attack
- The Hacker News: Silver Fox Exploits Microsoft-Signed WatchDog Driver
- The Hacker News: Silver Fox APT Uses Winos 4.0 Against Taiwanese Organizations
- Forescout: Healthcare Malware Hunt - Silver Fox Targets Philips DICOM Viewers
- Nidhogg Rootkit GitHub Repository
- Picus Security: Silver Fox APT Targets Public Sector via Trojanized Medical Software
- Industrial Cyber: Forescout Details Silver Fox Campaign Targeting Healthcare
Threats related to Silver Fox APT Tax-Themed Phishing Campaigns Deploying
Detection coverage for TL-2026-0276
As of 2026-03-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0276 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.