SilverFox ValleyRAT Attack Targets Japanese Industry via Phishing

Even a seemingly mundane invoice can initiate a devastatingly complex infection chain. Recently, the notorious SilverFox threat actor orchestrated this precise deceptive scheme against a prominent Japanese industrial firm. Ultimately, their objective was to surreptitiously deploy the ValleyRAT remote access trojan.
The Deceptive Phishing Lure and Trusted Infrastructure
According to an in-depth analysis of how Cato CTRL tracked SilverFox’s evolution, the insidious attack commenced with a meticulously crafted phishing email containing a fraudulent invoice. The attackers cleverly coerced the victim into downloading a malicious ZIP archive hosted on the legitimate QQ infrastructure. Subsequently, the loader dynamically retrieved supplementary payloads directly from Tencent’s cloud servers. The perpetrators strategically calculated that leveraging these highly trusted digital services would flawlessly camouflage their malicious data transmissions as routine, innocuous network traffic.
DLL Side-Loading Tactics
Within the compromised archive resided a deeply malicious library named PDFCORE8.dll, alongside one of two entirely legitimate executables: ConvertToPDF.exe or PDFDirect.exe. The threat actors deliberately positioned these files within the exact same directory. Occasionally, they further obscured their activities by renaming the legitimate application to MicrosoftEdgeUpdate.exe. Upon execution, the legitimate program inadvertently, yet automatically, loaded the adjacent counterfeit library. Cybersecurity professionals universally identify this sophisticated evasion technique as DLL side-loading.
Disabling Defenses via Vulnerable Drivers
The malicious PDFCORE8.dll operated as the central command hub for the ensuing attack sequence. Embedded within this library were three heavily encrypted, vulnerable system drivers: BootRepair.sys, EnPortv.sys, and wsftprm.sys. SilverFox strategically installed one of these drivers as a core system service. By exploiting this deep kernel-level access within Windows, the malware ruthlessly terminated active antivirus processes and essential security monitoring tools. Notably, threat intelligence analysts had never previously associated BootRepair.sys and EnPortv.sys with SilverFox’s known operational playbook.
Advanced Process Injection and Execution
Following the deliberate weakening of the system’s defensive perimeter, the malware executed a brilliant restorative maneuver. It proactively restored the critical ntdll.dll system library from a pristine, uncorrupted backup copy. This specific action effectively neutralized any API hooks previously embedded by active security software. Subsequently, the sophisticated loader spawned a suspended svchost.exe process, surreptitiously injected its malicious code directly into the allocated memory space, and aggressively hijacked the thread’s execution entry point. Consequently, ValleyRAT executed seamlessly while masquerading perfectly within a highly trusted, native Windows system process.
Ensuring Persistent Unauthorized Access
To guarantee unwavering, persistent access, SilverFox engineered a multifaceted survival strategy. They established a hidden scheduled task and securely entrenched the core payload and configuration settings deep within the Windows Registry. Furthermore, they implemented dual redundancy mechanisms for autonomous recovery. The primary loader continuously monitored and instantly relaunched the injected code if it ever terminated unexpectedly. Simultaneously, a robust, standalone command script meticulously audited the loader itself every 30 seconds, automatically initiating a full restoration process if it detected any disruptions.
Mitigation Strategies and Detection Indicators
During this specific investigated incident, the Cato defense platform successfully intercepted and neutralized PDFCORE8.dll prior to the final deployment of ValleyRAT. Security experts strongly advise network administrators to rigorously monitor the execution of ConvertToPDF.exe and PDFDirect.exe, particularly when launched from temporary system directories. Furthermore, defenders must scrutinize the suspicious loading of PDFCORE8.dll, the unauthorized installation of vulnerable drivers, any anomalous context modifications within suspended svchost.exe processes, and the writing of binary data to specific registry keys, notably HKCU\Console\0 and HKLM\SOFTWARE\IpDates_sun.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.