Foresiet, a leading innovator in Integrated Digital Risk Protection (IDRP), today released a comprehensive two-part threat intelligence report detailing a sophisticated, multi-country phishing operation. Attributed to the prominent China-nexus threat actor group Silver Fox, the active campaign weaponizes localized tax and invoice notifications to target corporate networks across India, Germany, Malaysia, and Japan.
Foresiet’s Threat Intelligence Team successfully intercepted and reverse-engineered the payload, exposing an evasive execution chain designed to bypass automated security sandboxes and standard endpoint protection platforms.
Advanced Sideloading and Fileless Delivery
The attackers initiate the breach using highly targeted phishing emails—such as a tax-scrutiny notice impersonating the Indian Income Tax Department. Once a victim clicks the link, they are routed to cloned infrastructure hosted on Alibaba Cloud in Hong Kong.
Rather than deploying an obvious malicious document, the landing page serves a 29MB ZIP archive containing a sophisticated three-file DLL-sideloading kit. The execution chain consists of:
-
The Decoy Host: A legitimately Authenticode-signed Overwolf/TeamSpeak helper binary.
-
The Evasion Layer: A heavily padded, 30.2MB trojanized DLL that mimics a real application plugin. The file size is artificially inflated with a maximum-entropy junk section specifically to evade signature-based anti-virus (AV) scanners.
-
The In-Memory Execution: Once executed by the trusted application, the loader reads an encrypted companion
.binstage, maps it directly into virtual memory, and leverages the .NET Common Language Runtime (CLR) to launch the payload.
By avoiding the disk and executing entirely in-memory, the malware leaves zero plaintext footprint on the endpoint, rendering traditional file-scanning defenses ineffective.
Severe Impact to Corporate Infrastructure
The final payload delivered via this fileless delivery mechanism is identified as a ValleyRAT-class (Winos) backdoor. This modular remote-access trojan grants the Silver Fox actors full interactive control over the compromised endpoint. Key capabilities include:
-
Real-time keystroke logging and clipboard monitoring.
-
Screen capture and file-transfer capabilities.
-
Theft of browser and enterprise application credentials.
-
A persistent foothold inside the corporate environment for lateral network movement.
Expert Commentary
“This operation highlights a deliberate shift by China-nexus threat actors toward blending localized social engineering with high-evasion, fileless techniques,” said the Foresiet Threat Intelligence Team. “By burying the malware inside the memory space of a signed, trusted application, Silver Fox effectively blinds legacy detection systems. Organizations can no longer rely solely on file-integrity checks; monitoring runtime behavior and suspicious memory allocations is vital.”
Availability and Defender Resources
Foresiet has published the full technical disassembly walkthrough, network infrastructure pivots, and a complete set of Indicators of Compromise (IOCs) to assist threat hunters and security teams worldwide in fortifying their perimeters.
The complete two-part threat intelligence report can be accessed on the Foresiet Research Hub:
-
Part I (The Infrastructure): https://foresiet.com/blog/fake-tax-notice-phishing-network/
-
Part II (The Payload Analysis): https://foresiet.com/blog/fake-tax-notice-campaign-valleyrat-unmasked/
About Foresiet
Foresiet simplifies digital risk management through its advanced Integrated Digital Risk Protection (IDRP) platform. Delivering real-time threat intelligence, dark web monitoring, and proactive attack surface management, Foresiet empowers global enterprises to secure their ecosystems against sophisticated cyber threats.
Media Contact:
Archana Naveen
[email protected]
