FortiGuard Labs has uncovered a series of targeted phishing campaigns in Taiwan attributed to the Silver Fox APT group. The operations use tax audits, e-invoice notifications, and fake tax software installers to lure victims into downloading malware.
The campaigns ultimately deploy Winos 4.0, also known as ValleyRat, along with malicious plugins designed for long-term control and defense evasion.
Researchers observed that attackers rotate domains and abuse cloud hosting services to distribute payloads, making static domain blocking ineffective.
Delivery methods identified over the past two months include malicious LNK files, DLL sideloading through legitimate applications, and Bring Your Own Vulnerable Driver (BYOVD) techniques using a signed kernel driver named wsftprm.sys.

Phishing Delivery and DLL Sideloading
In one campaign, victims received a RAR archive named “taxIs_RX3001.rar” containing a decoy document and a malicious shortcut file.
The LNK executed obfuscated commands via cmd.exe, copied the legitimate curl.exe utility under a renamed file, and downloaded a second-stage installer from a remote domain.
This installer extracted an embedded executable into C:\ProgramData\Golden, preparing the system for Winos 4.0 deployment.

A second campaign replaced LNK downloaders with DLL sideloading. Attackers distributed archives containing a legitimate executable paired with a malicious DLL.
When the trusted application launched, it loaded the attacker-controlled DLL, which initiated the next infection stage.
Analysis of debug paths inside the DLL revealed internal project names in Chinese, suggesting organized development workflows within the Silver Fox group.
Both infection chains are ultimately connected to the same command-and-control (C2) server infrastructure.
BYOVD and Security Evasion
Before executing its core payload, Winos 4.0 checks for administrative privileges. If necessary, it bypasses User Account Control (UAC) using a debug-object-hijacking technique involving computerdefaults.exe and RPC AppInfo calls.
The most notable tactic is BYOVD. The malware loads wsftprm.sys, a legitimately signed but vulnerable driver, to gain kernel-level access.
By dynamically invoking native APIs such as NtLoadDriver and RtlAdjustPrivilege from ntdll.dll, the malware bypasses standard monitoring controls.

It then checks registry settings related to the Windows Vulnerable Driver Blocklist and adapts accordingly. With kernel privileges, the malware scans running processes.
It terminates security products, including Microsoft Defender (MsMpEng.exe), Avast, AVG, and several Chinese security tools.
The C2 address is Base64-encoded within the binary. Once connected, Winos 4.0 downloads additional plugins directly into the Windows registry, enabling file management, screen capture, remote control, and system management without writing new files to disk.
Infrastructure analysis revealed shared domain registration details and development machine identifiers linking the campaigns to previous Silver Fox operations.
Researchers assess with high confidence that these activities constitute a coordinated, evolving effort by a specialized subgroup within the threat actor.
According to Fortinet, organizations are urged to treat tax-related attachments and invoice links with caution, enable driver blocklists, and monitor for suspicious DLL sideloading and unauthorized driver loading activity.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.