Call us Toll Free (USA): 1-833-844-9468     International: +1-603-280-4451 M-F 8am to 6pm EST

Foresiet Threat Intelligence Unmasks China-Nexus ‘Silver Fox’ Global Tax Phishing Campaign Deploying Fileless ValleyRAT

Foresiet, a leading innovator in Integrated Digital Risk Protection (IDRP), today released a comprehensive two-part threat intelligence report detailing a sophisticated, multi-country phishing operation. Attributed to the prominent China-nexus threat actor group Silver Fox, the active campaign weaponizes localized tax and invoice notifications to target corporate networks across India, Germany, Malaysia, and Japan.

Foresiet’s Threat Intelligence Team successfully intercepted and reverse-engineered the payload, exposing an evasive execution chain designed to bypass automated security sandboxes and standard endpoint protection platforms.

Advanced Sideloading and Fileless Delivery

The attackers initiate the breach using highly targeted phishing emails—such as a tax-scrutiny notice impersonating the Indian Income Tax Department. Once a victim clicks the link, they are routed to cloned infrastructure hosted on Alibaba Cloud in Hong Kong.

Rather than deploying an obvious malicious document, the landing page serves a 29MB ZIP archive containing a sophisticated three-file DLL-sideloading kit. The execution chain consists of:

  • The Decoy Host: A legitimately Authenticode-signed Overwolf/TeamSpeak helper binary.

  • The Evasion Layer: A heavily padded, 30.2MB trojanized DLL that mimics a real application plugin. The file size is artificially inflated with a maximum-entropy junk section specifically to evade signature-based anti-virus (AV) scanners.

  • The In-Memory Execution: Once executed by the trusted application, the loader reads an encrypted companion .bin stage, maps it directly into virtual memory, and leverages the .NET Common Language Runtime (CLR) to launch the payload.

By avoiding the disk and executing entirely in-memory, the malware leaves zero plaintext footprint on the endpoint, rendering traditional file-scanning defenses ineffective.

Severe Impact to Corporate Infrastructure

The final payload delivered via this fileless delivery mechanism is identified as a ValleyRAT-class (Winos) backdoor. This modular remote-access trojan grants the Silver Fox actors full interactive control over the compromised endpoint. Key capabilities include:

  • Real-time keystroke logging and clipboard monitoring.

  • Screen capture and file-transfer capabilities.

  • Theft of browser and enterprise application credentials.

  • A persistent foothold inside the corporate environment for lateral network movement.

Expert Commentary

“This operation highlights a deliberate shift by China-nexus threat actors toward blending localized social engineering with high-evasion, fileless techniques,” said the Foresiet Threat Intelligence Team. “By burying the malware inside the memory space of a signed, trusted application, Silver Fox effectively blinds legacy detection systems. Organizations can no longer rely solely on file-integrity checks; monitoring runtime behavior and suspicious memory allocations is vital.”

Availability and Defender Resources

Foresiet has published the full technical disassembly walkthrough, network infrastructure pivots, and a complete set of Indicators of Compromise (IOCs) to assist threat hunters and security teams worldwide in fortifying their perimeters.

The complete two-part threat intelligence report can be accessed on the Foresiet Research Hub:

About Foresiet

Foresiet simplifies digital risk management through its advanced Integrated Digital Risk Protection (IDRP) platform. Delivering real-time threat intelligence, dark web monitoring, and proactive attack surface management, Foresiet empowers global enterprises to secure their ecosystems against sophisticated cyber threats.

Media Contact:
Archana Naveen
[email protected]

Press Release by foresiet.com

Media Contact

ARCHANA NAVEEN


Cyber Defense Magazine July Edition for 2026


Published monthly by Cyber Defense Magazine, this resource shares a wealth of information to help you stay one step ahead of the next cyber threat.

Top InfoSec Innovators Awards for 2026 now open…

X