SilverFox Built Fake Software Sites That Know When Researchers Are Watching
Silver Fox operators delivered a Windows loader via WhatsApp while hiding payloads from security researchers.
Pelagosx analyzed a Silver Fox-linked Windows malware chain that began with a finance-themed WhatsApp message sent to Malaysian users. The ZIP contained an IMG with KuGou-signed PDF_C2089_20260911100446.exe, which loaded unsigned active_desktop_render_x64.dll, decrypted an 11,200-byte buffer, and called back to 134.122.155.135:443. The malware copied components to %APPDATA%\Microsoft\Update and created an HKCU Run value named MicrosoftUpdate. Related reporting links similar signed-binary sideloading to ValleyRAT, and NCC Group found sites that log download clicks and can hide payloads from researchers.