Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits

Silver Fox APT Tax-Themed Phishing Campaigns Deploying (TL-2026-0276), also tracked as Operation Silver Fox, is a high-severity advanced persistent threat campaign, first published 2026-03-24. It is attributed to Void Arachne (China) with high confidence, affects Microsoft Windows, maps to 29 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 40 indicators of compromise.

Key facts for TL-2026-0276

Threat ID
TL-2026-0276
Also known as
Operation Silver Fox, Void Arachne Campaign, ValleyRAT Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-03-24
Last reviewed
2026-03-24
Attribution
Void Arachne
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government, financial-services, healthcare, corporate, e-commerce, technology
Target regions
Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, Philippines
Detection rules
9
Indicators of compromise
40

Malware and tooling in Silver Fox APT Tax-Themed Phishing Campaigns Deploying

Malware and tooling: BlackMoon, CleverSoar, HoldingHands, Nidhogg, ValleyRAT

Silver Fox (Void Arachne), a China-based intrusion set active since 2022, conducts dual APT-espionage and cybercrime operations across the Asia-Pacific region. The group deploys ValleyRAT (Winos 4.0) via tax-themed phishing and SEO poisoning, abuses the Microsoft-signed WatchDog driver (amsdk.sys) for BYOVD privilege escalation and EDR termination, and leverages the Nidhogg kernel-mode rootkit for deep persistence and defense evasion.

How Silver Fox APT Tax-Themed Phishing Campaigns Deploying works

Silver Fox, also tracked as Void Arachne, SwimSnake, The Great Thief of Valley, and UTG-Q-1000, is a sophisticated China-based advanced persistent threat group that has evolved from financially motivated cybercrime to a dual-track operational model combining state-aligned espionage with criminal profit generation. Active since at least the second half of 2022, the group has conducted sustained campaigns targeting Chinese-speaking populations and organizations across Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, and the Philippines.

The group's primary payload is ValleyRAT, a modular C++ remote access trojan also known as Winos 4.0, which operates through a multi-stage infection chain. Initial access is achieved through tax-themed phishing emails impersonating national taxation authorities (particularly Taiwan's National Taxation Bureau), with malicious PDF or ZIP attachments containing DLL files. The group also employs SEO poisoning to distribute trojanized versions of legitimate software including Google Chrome, Microsoft Teams, Telegram, DeepSeek AI, and WPS Office.

ValleyRAT's infection chain involves multiple stages: (1) an initial loader with anti-VM, anti-sandbox, and hypervisor detection capabilities, (2) a beaconing module that performs privilege escalation via CMSTPLUA COM class abuse and fodhelper.exe UAC bypass, (3) a RuntimeBroker persistence component that manipulates the HKEY_CURRENT_USER\Software\Classes\mscfile\Shell\Open\Command registry key, (4) shellcode injection into svchost.exe for defense evasion, and (5) the final ValleyRAT payload with 16+ command capabilities including screen monitoring, keystroke logging, clipboard manipulation, USB device monitoring, and arbitrary shellcode execution.

A defining characteristic of Silver Fox's operations is their Bring Your Own Vulnerable Driver (BYOVD) campaign, first detected by Check Point Research in May 2025. The group exploits a previously unknown vulnerability in the WatchDog Antimalware driver (amsdk.sys, version 1.0.600), built on the Zemana Anti-Malware SDK. Despite being Microsoft-signed with a valid certificate, the driver lacks the FILE_DEVICE_SECURE_OPEN flag and fails to verify Protected Process Light (PPL) status, enabling arbitrary process termination of 192 hardcoded security products including 360 Safe, Kingsoft Antivirus, Tencent QQ PCMgr, and Kaspersky. When targeting Windows 7 systems, the group falls back to the known vulnerable Zemana driver (zam.exe). Notably, after the vendor released a patched driver (wamsdk.sys v1.1.100), Silver Fox attackers bypassed the patch by flipping a single byte in the RFC 3161 timestamp field, preserving the valid Microsoft signature while changing the file hash to evade blocklists.

The group's toolkit extends beyond ValleyRAT to include HoldingHands RAT (a Gh0st RAT variant deployed for premium espionage operations with 60-second heartbeat intervals and dynamic C2 updates), CleverSoar (an MSI-based installer that checks for Chinese/Vietnamese language settings before proceeding), the open-source Nidhogg kernel-mode rootkit (providing process hiding, file protection, registry concealment, AMSI bypass, ETW patching, and PP/PPL signature modification), and Blackmoon (financially motivated malware from the Chinese cybercrime ecosystem). A Python-based stealer impersonating WhatsApp was observed in 2026 campaigns.

C2 infrastructure is hosted across multiple providers including Alibaba Cloud, CTG Server LTD, and Chinese hosting providers. Communication employs HTTP File Server (HFS) for ValleyRAT delivery and TCP-based encrypted channels for Winos 4.0, with XOR encryption (keys including 0x60 and 0x36) and AES-256 for shellcode protection.

MITRE ATT&CK techniques used in TL-2026-0276

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data

defense-evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

discovery

T1057 Process Discovery; T1082 System Information Discovery

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

impact

T1496 Resource Hijacking

persistence

T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

initial-access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

resource-development

T1588 Obtain Capabilities

Affected products and versions in Silver Fox APT Tax-Themed Phishing Campaigns Deploying

  • Microsoft — Windows
    Vulnerable versions: Windows 7; Windows 10; Windows 11 (up to 25H2)
  • WatchDog Development — WatchDog Antimalware Driver (amsdk.sys)
    Vulnerable versions: 1.0.600
    Fixed in: 1.1.100 (partial)
  • Philips — DICOM Viewers
    Vulnerable versions: Multiple versions (trojanized copies)
  • Multiple — Chinese Antivirus Products (360 Safe, Kingsoft, Tencent QQ PCMgr)
    Vulnerable versions: All current versions targeted for termination

Remediation for Silver Fox APT Tax-Themed Phishing Campaigns Deploying

Patches

  • Update WatchDog Antimalware driver to latest version (note: v1.1.100 patch is incomplete)
  • Apply Microsoft Vulnerable Driver Blocklist updates when amsdk.sys is added
  • Ensure all endpoint protection products are updated to detect ValleyRAT variants

Immediate actions

  • Block all identified C2 IPs and domains at perimeter firewalls and DNS sinkholes
  • Hunt for amsdk.sys and wamsdk.sys driver artifacts on endpoints
  • Search for service names Termaintor and Amsdk_Service in Windows service registry
  • Monitor for rundll32.exe loading unsigned or unusual DLLs from AppData directories
  • Block known malicious file hashes at EDR and email gateway

Workarounds

  • Block amsdk.sys and wamsdk.sys driver loading via Windows driver blocklist policies
  • Restrict DeviceIoControl API calls from non-privileged processes
  • Monitor for Chinese/Vietnamese language checks in installer behaviors as CleverSoar indicator
  • Block Alibaba Cloud OSS and Youdao Cloud Notes domains if not business-required

Longer-term hardening

  • Deploy Windows Defender Application Control (WDAC) with driver blocklist including amsdk.sys hashes
  • Implement strict driver loading policies preventing unsigned or vulnerable kernel drivers
  • Enable PowerShell Script Block Logging (Event ID 4104) and Process Creation Auditing (Event ID 4688)
  • Deploy behavioral EDR detection for BYOVD patterns including DeviceIoControl abuse
  • Establish employee software catalogs to reduce SEO poisoning risk
  • Implement network segmentation to limit lateral movement from compromised endpoints

Weaknesses (CWE) in Silver Fox APT Tax-Themed Phishing Campaigns Deploying

CWE-269, CWE-863

Timeline of Silver Fox APT Tax-Themed Phishing Campaigns Deploying

  • Silver Fox APT first observed active, initially conducting financially motivated cybercrime operations targeting Chinese-speaking users
  • Silver Fox standardizes infection chains and begins systematic deployment of ValleyRAT (early variants) as primary RAT payload
  • Philips DICOM viewer trojanization campaign begins; 29 malicious samples identified between July 2024 and January 2025 targeting healthcare organizations
  • Rapid7 Labs identifies CleverSoar, a highly evasive MSI installer targeting Chinese and Vietnamese-speaking victims, deploying Winos 4.0 and Nidhogg rootkit
  • Taiwan-focused tax authority phishing campaign begins with emails impersonating National Taxation Bureau; PNGPlug loader first identified as part of group TTPs
  • Silver Fox APT Winos 4.0 campaign targeting Taiwanese organizations reported, using phishing emails with ZIP attachments containing malicious DLLs communicating with C2 at 206.238.221.60
  • Forescout publishes analysis of Silver Fox targeting healthcare sector with trojanized Philips DICOM viewers deploying ValleyRAT backdoors
  • ValleyRAT builder leaked publicly, enabling broader adoption; group continues operations with custom variants despite leak
  • Check Point Research discovers Silver Fox BYOVD campaign exploiting previously unknown vulnerability in Microsoft-signed WatchDog Antimalware driver (amsdk.sys v1.0.600)
  • BYOVD campaign loader sample compiled (SHA256: fc97ad46...), featuring anti-VM, anti-sandbox detection and dual-driver strategy for Windows 7 vs Windows 10/11
  • Nidhogg kernel-mode rootkit deployment integrated into Silver Fox operations, providing process hiding, AMSI bypass, ETW patching, and PP/PPL signature modification
  • Check Point Research publishes detailed analysis of Silver Fox BYOVD campaign; WatchDog vendor releases partial patch (wamsdk.sys v1.1.100)
  • HoldingHands RAT (Gh0st RAT variant) deployment begins for premium espionage operations; campaign expands to Japan and Malaysia
  • ReliaQuest reports Silver Fox fake Microsoft Teams campaign with Cyrillic false flags, distributing ValleyRAT via typosquatting domains (teamscn.com, teamszv.com)
  • Sekoia TDR publishes comprehensive analysis of Silver Fox tax-themed phishing campaigns spanning 2024-2026 across APAC, documenting evolved TTPs and dual APT/cybercrime model
  • As of 2026-05-29, Silver Fox/Void Arachne remains highly active with no takedown or arrests; Kaspersky/Securelist (May 2026) and The Hacker News documented fresh tax-themed campaigns deploying ValleyRAT plus the new ABCDoor backdoor and AtlasCross RAT into India and Russia. Its BYOVD amsdk.sys abuse persists (vendor patch bypassed via timestamp byte-flip) and tooling keeps evolving, confirming a live threat.

Sources cited for Silver Fox APT Tax-Themed Phishing Campaigns Deploying

Threats related to Silver Fox APT Tax-Themed Phishing Campaigns Deploying

Detection coverage for TL-2026-0276

As of 2026-03-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0276 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats