Inside Silver Fox, Part 3: From DLL Sideloading to ValleyRAT
The final user-mode link of the Silver Fox chain: the legitimately signed NtHandleCallback.exe side-loads a malicious log.dll that spawns three parallel threads — RC4-decrypting and running ValleyRAT in memory, deploying two kernel drivers for anti-forensics, and maintaining the Defender exclusion. ValleyRAT hides its C2 config and plugins in the HKCU\Console registry, so deleting files or blocking the C2 alone does not clean the host.