Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits — Threadlinqs Intelligence
As of 2026-05-30, Silver Fox APT Tax-Themed Phishing Campaigns Deploying ValleyRAT, BYOVD Driver Abuse, and Kernel Rootkits is a high-severity apt threat attributed to Void Arachne (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0276 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Void Arachne · China · ESPIONAGE
Silver Fox (Void Arachne), a China-based intrusion set active since 2022, conducts dual APT-espionage and cybercrime operations across the Asia-Pacific region. The group deploys ValleyRAT (Winos 4.0)
Silver Fox, also tracked as Void Arachne, SwimSnake, The Great Thief of Valley, and UTG-Q-1000, is a sophisticated China-based advanced persistent threat group that has evolved from financially motivated cybercrime to a dual-track operational model combining state-aligned espionage with criminal profit generation. Active since at least the second half of 2022, the group has conducted sustained campaigns targeting Chinese-speaking populations and organizations across Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, and the Philippines.
The group's primary payload is ValleyRAT, a modular C++ remote access trojan also known as Winos 4.0, which operates through a multi-stage infection chain. Initial access is achieved through tax-themed phishing emails impersonating national taxation authorities (particularly Taiwan's National Taxation Bureau), with malicious PDF or ZIP attachments containing DLL files. The group also employs SEO poisoning to distribute trojanized versions of legitimate software including Google Chrome, Microsoft Teams, Telegram, DeepSeek AI, and WPS Office.
ValleyRAT's infection chain involves multiple stages: (1) an initial loader with anti-VM, anti-sandbox, and hypervisor detection capabilities, (2) a beaconing module that performs privilege escalation via CMSTPLUA COM class abuse and fodhelper.exe UAC bypass, (3) a RuntimeBroker persistence component that manipulates the HKEY_CURRENT_USER\Software\Classes\mscfile\Shell\Open\Command registry key, (4) shellcode injection into svchost.exe for defense evasion, and (5) the final ValleyRAT payload with 16+ command capabilities including screen monitoring, keystroke logging, clipboard manipulation, USB device monitoring, and arbitrary shellcode execution.
A defining characteristic of Silver Fox's operations is their Bring Your Own Vulnerable Driver (BYOVD) campaign, first detected by Check Point Research in May 2025. The group exploits a previously unknown vulnerability in the WatchDog Antimalware driver (amsdk.sys, version 1.0.600), built on the Zemana Anti-Malware SDK. Despite being Microsoft-signed with a valid certificate, the driver lacks the FILE_DEVICE_SECURE_OPEN flag and fails to verify Protected Process Light (PPL) status, enabling arbitrary process termination of 192 hardcoded security products including 360 Safe, Kingsoft Antivirus, Tencent QQ PCMgr, and Kaspersky. When targeting Windows 7 systems, the group falls back to the known vulnerable Zemana driver (zam.exe). Notably, after the vendor released a patched driver (wamsdk.sys v1.1.100), Silver Fox attackers bypassed the patch by flipping a single byte in the RFC 3161 timestamp field, preserving the valid Microsoft signature while changing the file hash to evade blocklists.
The group's toolkit extends beyond ValleyRAT to include HoldingHands RAT (a Gh0st RAT variant deployed for premium espionage operations with 60-second heartbeat intervals and dynamic C2 updates), CleverSoar (an MSI-based installer that checks for Chinese/Vietnamese language settings before proceeding), the open-source Nidhogg kernel-mode rootkit (providing process hiding, file protection, registry concealment, AMSI bypass, ETW patching, and PP/PPL signature modification), and Blackmoon (financially motivated malware from the Chinese cybercrime ecosystem). A Python-based stealer impersonating WhatsApp was observed in 2026 campaigns.
C2 infrastructure is hosted across multiple providers including Alibaba Cloud, CTG Server LTD, and Chinese hosting providers. Communication employs HTTP File Server (HFS) for ValleyRAT delivery and TCP-based encrypted channels for Winos 4.0, with XOR encryption (keys including 0x60 and 0x36) and AES-256 for shellcode protection.
Weaknesses (CWE)
CWE-269, CWE-863
Target sectors: government, financial-services, healthcare, corporate, e-commerce, technology
Target regions: Taiwan, China, Vietnam, Japan, Malaysia, India, Indonesia, Singapore, Thailand, Philippines
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1588, T1566, T1566, T1204, T1059, T1547, T1547, T1053, T1574, T1548