SilverFox Built Fake Software Sites That Know When Researchers Are Watching
Silver Fox operators delivered a Windows loader via WhatsApp while hiding payloads from security researchers.
Pelagosx analyzed a Silver Fox-linked Windows malware chain that began with a finance-themed WhatsApp message sent to Malaysian users. The ZIP contained an IMG with KuGou-signed PDF_C2089_20260911100446.exe, which loaded unsigned active_desktop_render_x64.dll, decrypted an 11,200-byte buffer, and called back to 134.122.155.135:443. The malware copied components to %APPDATA%\Microsoft\Update and created an HKCU Run value named MicrosoftUpdate. Related reporting links similar signed-binary sideloading to ValleyRAT, and NCC Group found sites that log download clicks and can hide payloads from researchers.
- Finance-themed WhatsApp ZIP targeted Malaysian users and carried a signed executable.
- KuGou-signed launcher called an unsigned DLL that decrypted an 11,200-byte payload.
- Persistence used HKCU Run key MicrosoftUpdate under %APPDATA%\Microsoft\Update.
- Click-logging sites could withhold malicious installers from researchers and sandboxes.
- A related Silver Fox chain sideloaded ValleyRAT using signed Xunlei Thunder.exe.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 134.122.155.135 | ker @@RAPID_CFG_START@@ , a hard-coded callback endpoint at 134.122.155.135:443 , the Chinese string 默认分组, meaning “Default group,” and |
| sha256 | 9f2caeda208c9d729b44f31c32b5e1eeef18d84d6e36b04afe15d894d3809672 | tion, or document-review themes. IOCs Type Value ZIP SHA256 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 IMG SHA256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5 |
| sha256 | c1e184615241fe69db3bf4093a22c7c0bf5d6072d2f51e558142b844e871084f | 99A2B480020333DEB0F43364E9686CDA78B1243C62E4830D DLL SHA256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F Network 134.122.155.135:443 File PDF_C2089_20260911100446.e |
| sha256 | e2bf8b7cd396ee950a5b6911ea098c2e49d4ed002a6c04d5d660ccd4f7d66baa | 9B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 IMG SHA256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA EXE SHA256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA |
| sha256 | f712c2a8b4abf2e299a2b480020333deb0f43364e9686cda78b1243c62e4830d | 0A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA EXE SHA256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D DLL SHA256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E55 |
Full article717 words · extracted from gbhackers.com · click to collapse
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that can distinguish potential victims from security researchers.
Pelagosx recently investigated a related Windows malware delivery chain that began with a finance-themed WhatsApp message targeting Malaysian users.
The message urged recipients to forward a report for verification and open the attached archive on a computer.
The attachment, PDF_C2841_20260911100446.zip, contained an IMG disk image carrying a signed executable, PDF_C2089_20260911100446.exe, and an unsigned DLL, active_desktop_render_x64.dll.
The executable carried a valid Authenticode signature from Guangzhou Kugou Technology Co., Ltd. and used metadata identifying it as active_desktop_launcher.exe, associated with KuGou software.

PDF_C2841_20260911100446.zip(Source : Pelagosx).The adjacent DLL attempted to create a separate appearance of legitimacy: its version resources identified it as a “Desktop Window Manager Helper,” used the product name “Windows Desktop Extension,” and listed dwmapi.dll as its original filename.
That mismatch is central to the loader design. Static analysis found that the KuGou-branded launcher explicitly invokes SetDesktopMonitorHook() and ClearDesktopMonitorHook() from the unsigned DLL.
The exported function enters an obfuscated initialization routine that resolves APIs through hash-like values, decrypts stack-resident data using XOR operations, locates an executable PE section, and transforms a 0x2bc0-byte buffer before copying it into executable memory.
The number is not incidental. 0x2bc0 equals 11,200 bytes, exactly matching an 11,200-byte output buffer recovered from a successful BCryptDecrypt operation during dynamic analysis.
The decrypted content included the marker @@RAPID_CFG_START@@, a hard-coded callback endpoint at 134.122.155.135:443, the Chinese string 默认分组, meaning “Default group,” and additional configuration fields that remain unresolved.
At runtime, both components were copied into %APPDATA%\Microsoft\Update, a location designed to blend into ordinary Windows application data.
The malware then wrote a MicrosoftUpdate value beneath HKCU\Software\Microsoft\Windows\CurrentVersion\Run, creating user-level persistence via the Registry Run Keys / Startup Folder technique, MITRE ATT&CK T1547.001.
Pelagosx observed that, the campaign design allows attackers to selectively expose malicious downloads while collecting telemetry on who clicks, when they click, and where they are located.
SilverFox Built Fake Software
Pelagosx observed 96 outbound connection attempts to the direct-IP endpoint, with a highly regular retry interval of about three seconds.
A PDB artifact adds another clustering lead: D:\buildbot\build1\desktop_screen\build\bin\active_desktop_launcher_x64.pdb.

The references to buildbot, desktop_screen, and active_desktop_launcher_x64 may help defenders identify related samples, but they do not independently prove actor attribution.
The operational context nevertheless resembles recently documented Silver Fox activity.
CloudSEK reported a campaign targeting Indian entities that abused Xunlei’s validly signed Thunder.exe to sideload a malicious libexpat.dll, ultimately delivering ValleyRAT.
That intrusion chain similarly combined a trusted executable, a locally planted unsigned DLL, encrypted runtime payloads, anti-analysis controls, configurable C2 behavior, and registry-backed persistence.
The fake-site component is equally important. NCC Group found exposed Silver Fox link-management infrastructure that logged download-button clicks, including IP address, approximate location, timestamps, and application-specific campaign labels.
The infrastructure was used to track backdoored installers masquerading as popular tools such as Microsoft Teams, Telegram, Signal, OpenVPN, WPS, ToDesk, and HelloGPT.
Such telemetry gives operators a practical way to adjust delivery: a visitor from a target geography may receive a ZIP or installer, while traffic associated with scanners, sandbox networks, security firms, or repeated reconnaissance may receive nothing or a benign file.
This creates a serious visibility problem because public scanning and automated detonation can underrepresent the malware actually shown to selected victims.
Defenders should block 134.122.155.135:443, hunt for the two observed hashes, investigate unsigned DLLs launched beside signed third-party binaries, and alert on execution from %APPDATA%\Microsoft\Update.
Teams should also treat WhatsApp-delivered archives as an initial-access risk, especially when they use urgent finance, tax, verification, or document-review themes.
IOCs
| Type | Value |
|---|---|
| ZIP SHA256 | 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 |
| IMG SHA256 | E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA |
| EXE SHA256 | F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D |
| DLL SHA256 | C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F |
| Network | 134.122.155.135:443 |
| File | PDF_C2089_20260911100446.exe |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.