Actor
Silver Fox Campaign Distributes Malware via Spoofed Software Websites
2 rules 2 TTPs 15 IOCsThe threat cluster Silver Fox is targeting users with high-fidelity clone websites to distribute malicious installers that disable security features and deploy backdoors like ValleyRAT and Gh0st RAT.
Silver Fox Counterfeit Installer Campaign
3 TTPs 2 IOCsAn active campaign impersonates legitimate software vendors via look-alike websites to distribute dynamically generated malicious installers that evade detection and establish persistent access.
ValleyRAT Backdoor Distributed via Signed Adware
2 rules 2 TTPs 6 IOCsThe threat actor Silver Fox is distributing the ValleyRAT backdoor disguised as a signed QN Wallpaper adware application to leverage user-applied antivirus exclusions.
Silver Fox Spearphishing Campaign Targeting Japanese Firms During Tax Season
2 rules 5 TTPsThe Silver Fox threat actor is conducting a targeted spearphishing campaign against Japanese manufacturers and other businesses, exploiting the annual tax filing and organizational change season by sending emails containing malicious attachments that deploy ValleyRAT, leading to remote access, data theft, and persistence.