CTIPilot

Silver Fox

actor · actor:silver-fox

Actor operating the ValleyRAT (Winos 4.0) backdoor, with victim telemetry concentrated in China and India; established use of DLL sideloading through signed/legitimate applications as a delivery technique (Kaspersky Securelist, 2026-08-31).

Aliases: Void Arachne

Coverage timeline
2
first 2026-06-18 → last 2026-09-01
Peak priority
notable
2 notable
Sources cited
4
4 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
9
pinned v19.2 · see below
2026-06-182 appearances2026-09-01

ATT&CK techniques

9 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Privilege Escalation TA0004

T1055Process Injection×1

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1055Process Injection×1

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1055.012Process Injection: Process Hollowing×1

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Credential Access TA0006

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Discovery TA0007

T1518.001Software Discovery: Security Software Discovery×1

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Collection TA0009

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

T1115Clipboard Data×1

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

Evidence: 2026-09-01/valleyrat-winos4-qn-wallpaper-dll-sideload-defender-kill · ATT&CK page ↗

Story timeline

  1. 2026-09-01ValleyRAT (Winos 4.0) hides inside a re-signed Chinese wallpaper app: DLL sideloading, a self-restoring svchost injection, and a Windows Defender kill switch
    active-threatsKaspersky documents ValleyRAT distributed through a trojanized adware installer that disables Defender before loading the backdoor via DLL sideloading
  2. 2026-06-18China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network
    active-threats

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

related to

Where this entity is cited

  • active-threats2

Source distribution

  • cert.org.cn1 (25%)
  • news.risky.biz1 (25%)
  • securelist.com1 (25%)
  • thehackernews.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Silver Fox (2)

2026-09-01 · view entry permalink →

NOTABLENATOB1

ValleyRAT (Winos 4.0) hides inside a re-signed Chinese wallpaper app: DLL sideloading, a self-restoring svchost injection, and a Windows Defender kill switch

Kaspersky's Securelist published an analysis on 2026-08-31 of a ValleyRAT (Winos 4.0) distribution chain hidden inside a re-signed copy of QN Wallpaper, a genuine Chinese desktop-wallpaper and adware-bundling tool. The installer drops a modified QN Wallpaper build and adds it to autorun; before launching the adware, it flips the DisableAntiSpyware registry key to disable Windows Defender, relaunching itself via runas first if the logged-in user lacks administrator rights (Kaspersky Securelist, 2026-08-31; The Hacker News, 2026-08-31). QnWallpaper.exe then loads a malicious libcef.dll placed alongside it (DLL sideloading through a signed, trusted process) which decrypts an AES-encrypted ValleyRAT payload and hands it control via DllMain; the backdoor's own command-and-control configuration is stored as a reversed key:value string to defeat static string scanning (Kaspersky Securelist, 2026-08-31).

Runtime protections are read from the malware's own configuration and each can be switched on or off independently: marking the process critical (so killing it forces a system crash), injecting a watchdog into svchost that toggles its memory region from no-access to fully executable to relaunch the implant if interrupted, and enumerating open windows to detect security or traffic-analysis tooling before proceeding; a fourth resilience mechanism (restarting the backdoor on an unhandled exception) is always active regardless of that configuration (Kaspersky Securelist, 2026-08-31). Spyware functions run through DirectInput8 hooks for keystroke capture and a separate clipboard-capture routine, both writing collected data to disk; on operator command the backdoor can pull and execute additional modules, using process hollowing into svchost when a module arrives as raw shellcode. Kaspersky's account of this specific campaign is based on one installer submitted by a customer, and its report stops short of attaching a victim count to this adware-distribution route; separately, and across all of 2026 rather than this campaign alone, Kaspersky recorded over 100,000 detections of ValleyRAT and associated malware affecting more than 1,500 unique users, concentrated in China and India (The Hacker News, 2026-08-31). Kaspersky attributes the campaign to Silver Fox, an established ValleyRAT operator, on geography and payload grounds (Kaspersky Securelist, 2026-08-31). DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit, previously documented by Cato Networks against a Japanese manufacturer roughly five weeks earlier (The Hacker News, 2026-08-31). That campaign postdates a June 2026 Chinese police crackdown that arrested 67 people linked to Silver Fox across five provinces, evidence the group's operations continued despite the arrests; this QN Wallpaper campaign's own timing is not independently established beyond Kaspersky's 2026-08-31 publication date, so it cannot be dated relative to the arrests with the same confidence (Risky Bulletin, 2026-06-17).

Triage: genuine Chromium Embedded Framework processes (many legitimate desktop apps embed CEF) load libcef.dll from their own install directory and never inject code into svchost that toggles between no-access and executable memory states; that combination (a wallpaper or adware-class binary invoking CEF at all, paired with the svchost memory-protection change) is what separates this chain from ordinary CEF usage when that optional watchdog is present in the sample.

Over the course of 2026, we detected the ValleyRAT backdoor and its associated malware more than 100,000 times, with more than 1500 unique users affected, primarily in China and India.

After unpacking, the installer uses the DisableAntiSpyware registry key to disable Windows Defender and then launches QnWallpaper.exe.

This attack geography, combined with the use of the ValleyRAT backdoor, points to Silver Fox, a known operator of this malware family, as the likely group behind the campaign.

Kaspersky Securelist 2026-08-31

When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them.

The Hacker News 2026-08-31

Restarting on an unhandled exception. This protection mechanism is always active, regardless of the backdoor’s configuration.

Kaspersky Securelist 2026-08-31

Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates.

Risky Bulletin 2026-06-17
threat01 Sep 04:11Zmulti-sourceOpen finding ↗

2026-06-18 · view entry permalink →

NOTABLE

China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network

Chinese police arrested 67 suspects across five provinces in a June 2026 operation against Silver Fox (also tracked as Void Arachne, UTG-Q-1000 and TA4922) assessed as one of the most active crimeware operations targeting Chinese-speaking users (Risky Biz News, 2026-06-17). The arrests reportedly span the full criminal supply chain: the primary developer/seller of the Silver Fox (Winos) trojan, a variant developer, phishing-site operators, and fake-app download-site operators, with secondary RATs including ValleyRAT used for credential theft. A CNCERT/CC security alert issued on 2026-05-22 preceded the operation (CNCERT/CC, 2026-05-22).

threat18 Jun 05:10Zmulti-sourceOpen finding ↗