An ongoing malware campaign is targeting users through fraudulent software download sites, posing as reputable vendors and distributing harmful installers. This campaign has primarily affected China-based operations of multinational organizations and Chinese-speaking users, Microsoft reports.
Malware Targeting Multiple Sectors
The malware campaign has compromised numerous sectors, including healthcare, manufacturing, gaming, and education. The malicious installers, once executed, establish persistence, undermine security defenses, and connect to attacker-operated infrastructure. Microsoft links this activity to a Chinese threat cluster known as Silver Fox, which has a history of using fake vendor websites to spread malware like Gh0st RAT and ValleyRAT.
Fake Websites and Malicious Downloads
The counterfeit websites involved in this campaign are hosted on .com.cn and .hl.cn domains, with Chinese-language content designed to entice downloads of a ZIP archive from “gehie246[.]com.” These sites replicate legitimate vendor pages with a noticeable download prompt, and each download generates a new payload to evade detection.
The downloaded archive contains an installer that initiates the malware payload. Microsoft has identified a secondary method using the Windows Installer service to execute a random executable, further complicating detection. Persistence is achieved through tasks mimicking legitimate IT operations, while the malware alters Microsoft Defender settings, disables Windows Update services, and manipulates file permissions to avoid removal.
Command-and-Control and Ongoing Threats
Following these actions, the malware establishes command-and-control over non-standard ports, utilizing domains “iualef[.]net” and “oijfwe[.]net.” Although the campaign’s ultimate goal remains unclear, Microsoft has employed automated containment measures to mitigate its impact.
Recently, Kaspersky highlighted a similar threat involving a modified Chinese wallpaper tool to deploy ValleyRAT. The malware, operating under a legitimate application’s guise, captures sensitive data and executes advanced functions like system information collection and keystroke logging.
Concluding Thoughts on Cyber Threats
ValleyRAT’s deployment by Silver Fox, which targets organizations globally for espionage and financial gain, underscores the persistent threat of cyber attacks. According to a report by Expel, ValleyRAT has been linked to another group, CuboidalCanine, associated with the GoldenEyeDog network, which has shifted away from Gh0st RAT.
As cyber threats evolve, organizations must remain vigilant against these sophisticated attacks, leveraging robust security measures and staying informed about emerging threats.
