Leo

Security Analyst

Published research

Campaign

Silver Fox APT Campaign Analysis: Fake LINE Delivery via SEO Poisoning and Impersonation Sites

Silver Fox drops malicious installers via SEO poisoning and a fake LINE download site: victims land on a phishing page ranked below the official download page, an external script and short link pull a malicious archive, and after extraction the payload escalates via UAC, injects Chrome's elevation_service.exe through direct Native API syscalls, installs a SYSTEM-level persistence service, and injects sihost.exe to beacon to C2 43.102.44[.]165.

Malware

Inside Silver Fox, Part 2: Failure Engineering and the EDR Vanishing Act

Silver Fox's second-stage loader men.exe is built to clear the ground while EDR is still online: it uses BYOVD to load a vulnerable signed driver and force-terminate protection in Ring 0, adds a malicious driver to blind and delete EDR, and uses staged drops, delayed decryption, and DACL anti-forensics to pave the way for the ValleyRAT core.