Silver Fox Fake Software Sites and WhatsApp Malware Chain Hide Payloads From Researchers
Microsoft assesses with moderate confidence that counterfeit software download sites serving Windows malware are consistent with Silver Fox (Yinhu), while a separate finance-themed WhatsApp campaign delivered a KuGou-signed loader to a Malaysian user; NCC…
Microsoft assesses with moderate confidence that counterfeit software download sites serving malicious Windows installers — imitating browsers, security tools, and utilities — are consistent with Silver Fox, also called Yinhu, and does not attribute the activity to a nation-state. Observed compromises span several industries and mainly affect Chinese-speaking users. The payload archives can change between requests, weakening hash-based detection, and later stages create scheduled tasks, alter security exclusions, disable Windows Update, remove recovery copies, and contact attacker infrastructure. Separately, Pelagos (cited as Pelagosx by GBHackers and Pelagos Intel by Cyber Security News) analyzed a finance-themed WhatsApp message sent to a Malaysian recipient: the ZIP contained an IMG with a KuGou-signed PDF_C2089_20260911100446.exe, which loaded an unsigned active_desktop_render_x64.dll, decrypted an 11,200-byte buffer, and made repeated connections to 134.122.155.135:443. Persistence used an HKCU Run value named MicrosoftUpdate, with components copied to %APPDATA%\Microsoft\Update. GBHackers links similar signed-binary sideloading to ValleyRAT, including a related Silver Fox chain that sideloaded ValleyRAT using a signed Xunlei Thunder.exe, and cites NCC Group's finding that the fake sites log download clicks and can hide malicious installers from researchers and sandboxes. Cyber Security News notes the fake-site and WhatsApp chains are not shown to share infrastructure, while GBHackers presents the WhatsApp chain as Silver Fox-linked — a linkage the two reports do not fully resolve.
- Microsoft assesses with moderate confidence that counterfeit software download sites serving malicious Windows installers are consistent with Silver Fox, also called Yinhu, and does not attribute the activity to a nation-state.
- Observed compromises span several industries and mainly affect Chinese-speaking users.
- The fake sites imitate browsers, security tools, and utilities; ZIP payloads can be rebuilt per request, weakening hash-based detection.
- Later-stage payloads create scheduled tasks, alter security exclusions, disable Windows Update, remove recovery copies, and contact attacker infrastructure.
- The WhatsApp chain began with a finance-themed message to a Malaysian recipient; the ZIP contained an IMG holding the KuGou-signed PDF_C2089_20260911100446.exe.
- The signed launcher loaded the unsigned active_desktop_render_x64.dll, which decrypted an 11,200-byte payload and made repeated connections to 134.122.155.135:443.
- Persistence used an HKCU Run key named MicrosoftUpdate, with components copied to %APPDATA%\Microsoft\Update.
- NCC Group found the fake sites log download clicks and can withhold malicious installers from researchers and sandboxes.
Coverage timelineoldest first · each row is one article
- · 19h agoSilverFox Built Fake Software Sites That Know When Researchers Are Watching
GBHackers· 61
Silver Fox operators delivered a Windows loader via WhatsApp while hiding payloads from security researchers.
- · 15h agoSilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Cyber Security News· 72
Microsoft ties Silver Fox fake download sites to Windows malware mainly hitting Chinese-speaking users.