ThreatCluster

Silver Fox APT Deploys ValleyRAT via Fake Installers Targeting China

First seen 5 Dec 2025, 02:43 UTC GbhackersWebpronews 50

Article Content

Browse articles
ThreatCluster

The Silver Fox APT group has launched a campaign targeting users in China by distributing malware through fake installers of popular applications, including Microsoft Teams. The malware, known as ValleyRAT, employs advanced evasion techniques to compromise systems and maintain persistent access. This operation showcases sophisticated methods such as kernel-level driver abuse and multi-stage obfuscation.