Cybersecurity researchers are tracking a highly aggressive, ongoing campaign by the SilverFox threat group, which is currently deploying an advanced variant of the ValleyRAT malware.
While traditional Remote Access Trojans typically rely on a brief two- or three-stage infection process, this new operation is notable for executing an incredibly complex eight-stage kill chain.
The attack culminates in the installation of a custom kernel-level rootkit that receives operational commands directly from the user-mode RAT.
This live campaign demonstrates a significant escalation in the group’s technical sophistication and evasion capabilities.
The infection sequence is designed to continuously dismantle system defenses while hiding its core components from traditional security software.
The attackers initiate the compromise by distributing trojanized software installers that abuse legitimate, digitally signed executables.
This allows them to bypass initial security checks and begin a meticulous, multi-step deployment process.
SilverFox Deploys Kernel Rootkit
Stage one utilizes the abused legitimate executables to perform dynamic link library sideloading, establishing the initial foothold on the target machine.
Stage two turns off local telemetry by bypassing Event Tracing for Windows and the Antimalware Scan Interface, while concurrently extracting a payload concealed within the pixel channels of a PNG image via steganography.
Stage three forces privilege escalation on the compromised endpoint and decodes additional malicious instructions hidden inside a second steganographic PNG file.
Stage four unpacks and executes nested Donut shellcode directly within system memory, keeping the attack fileless to avoid triggering disk-based heuristic scans.
Beyond the intricate delivery mechanism, this ValleyRAT campaign also features aggressive data exfiltration and persistence capabilities.
The malware includes specialized modules designed to monitor the system clipboard for cryptocurrency wallet addresses and hijack transactions on the fly.
It also actively targets local Telegram installations to quietly steal user credentials, session data, and private communications.
To ensure the malware can adapt to new requirements, the attackers can deliver additional malicious plugins directly to the infected machine over the established named pipes, GenThreatLabs said.
To counter detection efforts, the SilverFox threat actors rely heavily on rapid polymorphism and structural rotation.
Researchers monitoring the live campaign observed the threat group recompiling 13 distinct malware samples for a single targeted victim over just 12 days.
This constant alteration of the malware’s cryptographic hash renders standard signature-based detection nearly useless. Furthermore, the malware employs a daily rotation strategy for its file paths.
The core files constantly shift their locations within the local driver directory, changing their operational base every 24 hours.
This high-frequency adaptation ensures that static indicators of compromise quickly become obsolete, making incident response, threat hunting, and final remediation exceptionally challenging for enterprise security teams.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
