The article discusses a new cyberattack campaign by the Silver Fox group, which targets Chinese-speaking users. The attackers have created a fake Telegram language pack installer that hides ValleyRAT malware. Here are the key points:
-
Attack Vector:
- The attack uses a fake Telegram Chinese language pack installer.
- When executed, it installs MSI (Microsoft Installer) files.
-
Malware Delivery:
- After installation, VBScript custom actions launch PowerShell to execute malicious scripts.
- These scripts download and install the ValleyRAT malware from command-and-control servers.
-
Techniques Used:
- The attackers use DLL sideloading through a legitimate, signed ByteDance binary (SodaMusicLauncher.exe) if Qihoo 360 or Tencent PC Manager antivirus products are detected.
- If no major antivirus is present, the payload executes directly from the C drive.
-
Command-and-Control Servers:
- The malware communicates with command-and-control servers at IP address 118.107.43.65 and broader netblock 118.107.40.0/21.
-
**Detection and
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





