6h ago · hacker-news
A malware campaign attributed to the Chinese threat cluster Silver Fox (aka Yinhu) is distributing malicious fake software installers through spoofed vendor websites, primarily targeting Chinese-speaking users and multinational organizations in China. The installers deploy Gh0st RAT and ValleyRAT, which disable Windows Update services, weaken Microsoft Defender, and establish command-and-control communication via non-standard ports. The payloads use DLL sideloading and masquerade as legitimate installers to bypass security controls, enabling keystroke logging, clipboard theft, and remote system control.