A sophisticated malware campaign utilizing counterfeit Google Chrome websites has been discovered distributing ValleyRAT, a remote access trojan. The operation, attributed to the threat actor Silver Fox, primarily targets Chinese-speaking regions including Hong Kong, Taiwan, and Mainland China.
Security researchers at Morphisec have identified that the attackers specifically focus on employees in finance, accounting, and sales departments, seeking access to sensitive organizational data. The campaign combines ValleyRAT with other malware variants, including Purple Fox and Gh0st RAT.
The attack methodology involves:
– Fake Google Chrome download pages
– Malicious ZIP archives containing “Setup.exe”
– DLL sideloading through legitimate Douyin (Chinese TikTok) executable
– Implementation of “tier0.dll” for ValleyRAT deployment
– Usage of “sscronet.dll” for process termination control
ValleyRAT, a C++ based trojan compiled in Chinese, offers sophisticated capabilities including:
– Screen monitoring
– Keystroke logging
– System persistence
– Remote command execution
– Process enumeration
– Arbitrary file execution
The malware leverages DLL search order hijacking through signed executables for payload injection, demonstrating advanced evasion techniques. This campaign represents a continuing trend of sophisticated cyber attacks targeting Chinese-speaking regions through software supply chain compromise.
