CODERED VTA

Silver Fox Malware Campaign Uses WhatsApp Lures to Target Malaysian Desktop Users

High
Server room with blue lights
Photo by Taylor Vick on Unsplash

An active malware delivery chain aimed at users in Malaysia has been observed arriving through WhatsApp rather than email, using a finance-themed lure that urges the recipient to forward a report for verification and open the attachment on a computer. The attachment, a ZIP archive named PDF_C2841_20260911100446.zip, contains an IMG disk image holding two Windows components that work as a pair. The first is PDF_C2089_20260911100446.exe, a 102KB executable carrying a valid Authenticode signature from Guangzhou Kugou Technology Co., Ltd. and version metadata identifying it as active_desktop_launcher.exe from the KuGou product line. The second is active_desktop_render_x64.dll, a 5MB unsigned library that falsely presents itself through its version resources as a Microsoft Desktop Window Manager Helper with the original filename dwmapi.dll. The tradecraft, tooling layout and configuration handling align closely with Silver Fox activity previously documented against targets in India, though this is a related cluster rather than an exact campaign match.

The chain relies on a trusted, validly signed binary to do the loading work. Decompilation of the launcher recovers a compact wrapper that does almost nothing on its own — it simply imports and calls two exported functions from the companion DLL, SetDesktopMonitorHook() and ClearDesktopMonitorHook(), then returns. Inside the DLL, SetDesktopMonitorHook() sets an internal state value and transfers execution into an obfuscated initialization routine that resolves Windows APIs through hash-like identifiers instead of plain import names, decodes stack-local data with XOR, locates an executable PE section, and performs an XOR-style byte transformation across a 0x2bc0-byte buffer before copying the transformed data into executable memory. That 0x2bc0 figure is 11,200 bytes in decimal, and runtime instrumentation captured a successful BCryptDecrypt operation producing an output buffer of exactly 11,200 bytes — strong evidence that the static transformation and the runtime decryption are the same unpacking step. The decrypted blob turned out to be a structured configuration block opening with the marker @@RAPID_CFG_START@@ and containing the direct-IP endpoint 134.122.155.135, port 443, the Chinese string 默认分组 meaning Default group, and further unresolved fields. At runtime both files are copied via CopyFileW into %APPDATA%MicrosoftUpdate, a Registry Run value named MicrosoftUpdate is written under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence, and the process then makes repeated Winsock send attempts to 134.122.155.135:443 — 96 connection attempts recorded at a highly regular interval of roughly three seconds. A build artifact left in the executable, the PDB path D:buildbotbuild1desktop_screenbuildbinactive_desktop_launcher_x64.pdb, offers a useful clustering term for hunting related samples.

The strategic problem here is the abuse of a legitimate code-signing identity. Because the launcher carries a signature Windows reports as valid, application allow-listing and reputation-based controls that key on signer identity are far less likely to intervene, and the malicious logic never touches disk in unsigned executable form once the DLL side-loads and unpacks itself in memory. Choosing WhatsApp as the delivery channel also sidesteps the mail gateway entirely, landing the archive on a personal device or an unmanaged endpoint before the file reaches a corporate machine; the lure's explicit instruction to open the attachment on a computer shows that pivot is intentional. The use of a hard-coded direct IP over port 443 rather than a domain means DNS-based blocking and domain reputation feeds provide no coverage, while the fixed three-second retry cadence is a distinctive behavioural signal for anyone watching outbound flows. Configuration markers such as @@RAPID_CFG_START@@ and the Default group label point to a builder-driven, operator-configurable commodity RAT, which implies multiple parallel campaigns and additional victim groups beyond the one observed. Persistence is already established on infected hosts through the Run key, the C2 is live, and the delivery mechanism remains in use, so this should be treated as ongoing rather than historical activity.

Attack Surface

Messaging, Endpoint, Endpoint OS

Tactics

Initial Access, Execution, Defense Evasion, Persistence, Command and Control

Techniques

  • T1566.001 – Phishing: Spearphishing Attachment
  • T1204.002 – User Execution: Malicious File
  • T1553.002 – Subvert Trust Controls: Code Signing
  • T1574.001 – Hijack Execution Flow: DLL
  • T1547.001 – Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • T1055 – Process Injection
  • T1027 – Obfuscated Files or Information
  • T1140 – Deobfuscate/Decode Files or Information
  • T1036.005 – Masquerading: Match Legitimate Name or Location
  • T1071.001 – Application Layer Protocol: Web Protocols
  • T1105 – Ingress Tool Transfer
  • T1573 – Encrypted Channel

SuperPRO's Threat Countermeasures Procedures

  1. Block and alert on outbound traffic to 134.122.155.135 on TCP/443 at the perimeter firewall and proxy, and hunt historic netflow for any host making repeated connections to that IP at a fixed ~3 second interval.
  2. Hash-block the two payload components in EDR: PDF_C2089_20260911100446.exe (SHA-256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D) and active_desktop_render_x64.dll (SHA-256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F).
  3. Create a detection rule for RegSetValueExW writes creating the value name MicrosoftUpdate under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and audit existing hosts for that value pointing into %APPDATA%MicrosoftUpdate.
  4. Alert on any executable or DLL written to or launched from the path %APPDATA%MicrosoftUpdate — this directory is not a legitimate Windows update location and the chain stages both files there via CopyFileW.
  5. Flag process launches of unsigned DLLs named active_desktop_render_x64.dll or any DLL whose version resources claim OriginalFilename dwmapi.dll while loading from a user-writable directory rather than System32.
  6. Block .img, .iso and .vhd disk-image attachments delivered inside ZIP archives at the mail gateway and via endpoint policy, and disable automatic mounting of disk images for standard users using the Group Policy setting that removes the Windows Explorer mount handler.
  7. Add the signer Guangzhou Kugou Technology Co., Ltd. and the PDB clustering strings buildbotbuild1desktop_screen and active_desktop_launcher_x64.pdb to threat-hunting queries, and review application allow-list policies that grant execution purely on valid Authenticode signature.

Source

Code Red Cyber / VTA – coderedcyber.ai