<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>malware on Himanshu Anand :: Security &amp; Other Notes</title>
    <link>https://blog.himanshuanand.com/tags/malware/</link>
    <description>Recent content in malware on Himanshu Anand :: Security &amp; Other Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 18 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.himanshuanand.com/tags/malware/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>someone is filing your GST return, and it is not your CA</title>
      <link>https://blog.himanshuanand.com/2026/08/someone-is-filing-your-gst-return-and-it-is-not-your-ca/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      
      <guid>https://blog.himanshuanand.com/2026/08/someone-is-filing-your-gst-return-and-it-is-not-your-ca/</guid>
      <description>Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and conclusions are my own.
TLDR Found an unreported Silver Fox campaign serving ValleyRAT to Indian taxpayers with a fake &amp;ldquo;GSTR-3B overdue&amp;rdquo; lure, timed to the real 20 August GST filing deadline. The delivery is a disk image containing a genuinely Microsoft-signed SystemSettings.exe that sideloads a patched SystemSettings.dll (Microsoft cert still attached, hash broken cute).</description>
      <content>&lt;p&gt;&lt;em&gt;Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and conclusions are my own.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;tldr&#34;&gt;TLDR&lt;/h2&gt;
&lt;p&gt;Found an &lt;strong&gt;unreported Silver Fox campaign&lt;/strong&gt; serving ValleyRAT to Indian taxpayers with a fake &amp;ldquo;GSTR-3B overdue&amp;rdquo; lure, timed to the real 20 August GST filing deadline. The delivery is a disk image containing a &lt;em&gt;genuinely Microsoft-signed&lt;/em&gt; SystemSettings.exe that sideloads a &lt;em&gt;patched&lt;/em&gt; SystemSettings.dll (Microsoft cert still attached, hash broken  cute). Stage 2 injects into RuntimeBroker.exe with a full UACMe kit, a Defender tamperer and an AV process-killer. Reversed both stages, recovered the full config: &lt;strong&gt;3 C2 endpoints, a dormant backup domain, build date Aug 2 2026,and a 15 subdomain delivery platform that is serving per victim lure links as I type this.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;how-this-started&#34;&gt;how this started&lt;/h2&gt;
&lt;p&gt;I was doing something completely different measuring how much India-targeted APT tooling even shows up in public sandbox feeds (spoiler: the APT36 stuff barely does, that is a whole separate post). While tag-hunting &lt;code&gt;valleyrat&lt;/code&gt; on &lt;a href=&#34;https://app.any.run/submissions&#34;&gt;ANY.RUN&amp;rsquo;s public submissions&lt;/a&gt;, the feed was the usual suspects: fake VPN installers, something literally named &lt;code&gt;jiazaiqitest.exe&lt;/code&gt; (加载器测试  &amp;ldquo;loader test&amp;rdquo;, they are not even trying), the usual Chinese-locale noise.&lt;/p&gt;
&lt;p&gt;And then this, submitted &lt;strong&gt;7 August 2026&lt;/strong&gt;:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;GST_Filing_Overdue_GSTR-3B_GSTIN27ABCDE1234F1Z5_Due_20082026.zip
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If you are not Indian: GSTR-3B is the monthly GST return every registered business files, GSTIN is the tax ID, and the 20th of the month is the actual deadline. The GSTIN in the filename even uses the correct format  &lt;code&gt;27&lt;/code&gt; is Maharashtra. Somebody on the operator side &lt;em&gt;did the homework&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Sandbox verdict: &lt;strong&gt;Malicious&lt;/strong&gt;. Tracker: Backdoor, RAT, ValleyRAT. Tags: &lt;code&gt;silverfox&lt;/code&gt;, &lt;code&gt;winos&lt;/code&gt;, &lt;code&gt;processkiller&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Public coverage of this file, its C2s or a GST lure wave: &lt;strong&gt;zero&lt;/strong&gt;. Nada, One lonely urlscan scan of the delivery domain.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/malware-free-realestate.jpg&#34; alt=&#34;&amp;amp;ldquo;it&amp;amp;rsquo;s free real estate&amp;amp;rdquo;  finding unreported APT infra in a public feed&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;the-actor-you-already-know&#34;&gt;the actor you already know&lt;/h2&gt;
&lt;p&gt;Quick refresher, because context matters. &lt;strong&gt;Silver Fox&lt;/strong&gt; (SwimSnake / Void Arachne / 银狐) is a China-nexus crew running &lt;strong&gt;ValleyRAT&lt;/strong&gt; (built on the WinOS 4.0 framework plugin-based RAT, keylogger, screen capture, the works). The group has been &lt;a href=&#34;https://www.cloudsek.com/blog/silver-fox-targeting-india-using-tax-themed-phishing-lures&#34;&gt;targeting Indian users since at least December 2025 with Income Tax Department lures&lt;/a&gt; (nice work by CloudSEK on that one) and separately running &lt;a href=&#34;https://www.nccgroup.com/research-blog/black-hole-of-trust-seo-poisoning-in-silver-fox-s-space-odyssey/&#34;&gt;SEO-poisoned fake software installers&lt;/a&gt; (NCC Group) and even a &lt;a href=&#34;https://reliaquest.com&#34;&gt;Russian false flag operation&lt;/a&gt; to muddy attribution. Their comfort food: DLL sideloading behind signed binaries, disposable free-domain C2, tax-season timing.&lt;/p&gt;
&lt;p&gt;What nobody had reported: a GST wave, this infrastructure or this exact sideload pair. Until the ANY.RUN feed coughed it up.&lt;/p&gt;
&lt;h2 id=&#34;unboxing-the-lure&#34;&gt;unboxing the lure&lt;/h2&gt;
&lt;p&gt;The ZIP contains a &lt;strong&gt;1.2 MB &lt;code&gt;.img&lt;/code&gt; disk image&lt;/strong&gt;. Why a disk image? Because files inside a mounted image don&amp;rsquo;t inherit Mark-of-the-Web the &amp;ldquo;this came from the internet, are you sure?&amp;rdquo; prompts never fire. Double click and it mounts like a USB drive. Very 2024 technique still printing money in 2026.&lt;/p&gt;
&lt;p&gt;Inside the image, two files:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;GST_Filing_Overdue_GSTR-3B_..._Due_20082026.exe   98 KB
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;SystemSettings.dll                                59 KB
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;And here is where it gets spicy.&lt;/p&gt;
&lt;p&gt;Signature check:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;EXE:  VALID signature  Microsoft Corporation
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;      OriginalFilename: SystemSettings.exe (the real Windows Settings app, renamed)
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;DLL:  Microsoft cert attached… but HashMismatch
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The EXE is the &lt;em&gt;actual, legit, Microsoft-signed&lt;/em&gt; SystemSettings.exe. The DLL &lt;em&gt;was&lt;/em&gt; a real Microsoft binary  until someone patched it. The signature is still there, it just no longer validates. To a reputation based filter, both files &amp;ldquo;are Microsoft.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;No unsigned attacker code ever touches disk.&lt;/strong&gt; The whole stage-1 lives inside a tampered system DLL that a signed Microsoft process happily loads.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/windows-or-malware.jpg&#34; alt=&#34;not sure if Windows component… or malware&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;ghidra-time-the-dll-that-lies&#34;&gt;ghidra time: the dll that lies&lt;/h2&gt;
&lt;p&gt;I opened the DLL in Ghidra DllMain? Stock CRT boilerplate Exports? Stubs If your static scanner keys on entry point weirdness, it sees nothing  the implant is grafted into the CRT init path instead.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/ghidra-entry.png&#34; alt=&#34;Ghidra CodeBrowser: the most innocent DllMain you will ever see&#34;&gt;&lt;/p&gt;
&lt;p&gt;The fun starts in the orchestrator (&lt;code&gt;FUN_180003030&lt;/code&gt;). This function never touches a readable string. Everything  API names, C2, paths  is built as &lt;strong&gt;stack constants&lt;/strong&gt;, decoded in place, used, zeroed. With junk noop calls sprinkled between real instructions, because apparently my time is worthless.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/ghidra-orchestrator.png&#34; alt=&#34;The orchestrator: stack-string city, population me&#34;&gt;&lt;/p&gt;
&lt;p&gt;The decoder is a single-byte XOR:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;kt&#34;&gt;void&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;decode&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;byte&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;*&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;buf&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;uint&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;len&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    &lt;span class=&#34;k&#34;&gt;for&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;i&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;len&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;++&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;buf&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;i&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;^=&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0x70&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;First decoded block resolves &lt;code&gt;kernel32.dll&lt;/code&gt; -&amp;gt; &lt;code&gt;GetModuleHandleA&lt;/code&gt;. Standard &amp;ldquo;resolve everything at runtime so the import table says nothing&amp;rdquo; tradecraft:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/ghidra-stackstrings.png&#34; alt=&#34;Stack strings decoding to kernel32.dll before GetModuleHandleA&#34;&gt;&lt;/p&gt;
&lt;p&gt;And then  my favorite screenshot of this entire analysis  the C2, hiding in a &lt;code&gt;movabs&lt;/code&gt;:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/ghidra-c2-constants.png&#34; alt=&#34;MOVABS RAX, 0x5e13080a14030919  the XOR&amp;amp;rsquo;d C2 being assembled&#34;&gt;&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-asm&#34; data-lang=&#34;asm&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;180003234&lt;/span&gt;  &lt;span class=&#34;nf&#34;&gt;MOV&lt;/span&gt;  &lt;span class=&#34;no&#34;&gt;RAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0x5e13080a14030919&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;180003246&lt;/span&gt;  &lt;span class=&#34;nf&#34;&gt;MOV&lt;/span&gt;  &lt;span class=&#34;no&#34;&gt;RAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0x13135e05155e13&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;180003263&lt;/span&gt;  &lt;span class=&#34;nf&#34;&gt;MOV&lt;/span&gt;  &lt;span class=&#34;no&#34;&gt;EDX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0xd&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;180003268&lt;/span&gt;  &lt;span class=&#34;nf&#34;&gt;CALL&lt;/span&gt; &lt;span class=&#34;no&#34;&gt;decode&lt;/span&gt;        &lt;span class=&#34;c1&#34;&gt;; 13 bytes
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Thirteen bytes, XOR 0x70: &lt;code&gt;iysdzxc.eu.cc&lt;/code&gt;. Which is &lt;em&gt;exactly&lt;/em&gt; the domain the sandbox saw on the wire. Static and dynamic analysis shaking hands.&lt;/p&gt;
&lt;p&gt;But wait  the DLL&amp;rsquo;s &lt;code&gt;.rdata&lt;/code&gt; has a full XOR&amp;rsquo;d config block. Decoding it:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;iysdzxc.eu.cc        &amp;lt;- primary delivery domain (sandbox saw this one)
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;/d/ee2b12fbd661      &amp;lt;- URI path
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bdgsewa.eu.cc        &amp;lt;- BACKUP DOMAIN (sandbox never saw this  nobody had it)
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;/d/6c42e162ed46      &amp;lt;- second path
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;GetTickCount         &amp;lt;- hello timing checks
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;bdgsewa.eu.cc&lt;/code&gt; had &lt;strong&gt;zero&lt;/strong&gt; hits anywhere on the internet. A dormant failover channel, pulled out of the binary with tweezers. This is why you do static analysis even when the sandbox report looks &amp;ldquo;complete.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The downloader itself is dressed up as Edge 131  full fake UA, proper Accept headers… and one beautiful mistake: &lt;code&gt;Accept-Language: en-US,en;q=0.9,zh-CN;q=0.8&lt;/code&gt;. A Chinese-locale fallback copied straight from the operator&amp;rsquo;s dev template. Attribution fibers are the best fibers.&lt;/p&gt;
&lt;p&gt;The downloaded stage 2 is then mapped into memory by a &lt;strong&gt;hand-rolled reflective PE loader&lt;/strong&gt; (copy sections, VirtualProtect per section). It never exists as a file. Of course.&lt;/p&gt;
&lt;h2 id=&#34;stage-2-reading-valleyrats-diary&#34;&gt;stage 2: reading valleyrat&amp;rsquo;s diary&lt;/h2&gt;
&lt;p&gt;ANY.RUN showed the lure EXE injecting into &lt;strong&gt;RuntimeBroker.exe&lt;/strong&gt;  and bless them, the task exposes &lt;strong&gt;process dumps&lt;/strong&gt; of the injected regions. Downloaded both, opened in Ghidra the dump is where this RAT stops pretending.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The config&lt;/strong&gt; (UTF-16, sitting right there):&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;|p1:103.97.131.179|o1:8888|t1:1|p2:103.97.131.179|o2:6666|t2:1|p3:103.97.128.141|o3:7777|t3:1|dd:1|cl:1|fz:默认|
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;|bb:1.0|bz:2026. 8. 2|jp:0|bh:0|ll:0|dl:0|
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Translation: three C2 endpoints  &lt;code&gt;103.97.131.179:8888&lt;/code&gt; (this exact one showed up in sandbox traffic), plus &lt;strong&gt;&lt;code&gt;:6666&lt;/code&gt; and &lt;code&gt;103.97.128.141:7777&lt;/code&gt; which are NOT in any public feed&lt;/strong&gt;. Build date &lt;strong&gt;2026-08-02&lt;/strong&gt;  five days before the lure dropped. And &lt;code&gt;fz:默认&lt;/code&gt;  the victim group field is literally Chinese for &amp;ldquo;default.&amp;rdquo; Operator console confirmed Chinese. We knew, but it&amp;rsquo;s nice when they label it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The toolkit.&lt;/strong&gt; The dumped module&amp;rsquo;s manifest identifies itself as &lt;strong&gt;&amp;ldquo;Akagi&amp;rdquo;&lt;/strong&gt;  as in &lt;a href=&#34;https://github.com/hfiref0x/UACME&#34;&gt;UACMe&lt;/a&gt;, the open-source UAC-bypass collection, complete with the aircraft-carrier description string intact. Alongside it: references to &lt;code&gt;computerdefaults.exe&lt;/code&gt;, &lt;code&gt;dccw.exe&lt;/code&gt;, &lt;code&gt;tracerpt.exe&lt;/code&gt; (signed auto-elevating Microsoft binaries  the UAC-bypass menu), Defender&amp;rsquo;s private COM interfaces &lt;code&gt;MpManagerOpen&lt;/code&gt;/&lt;code&gt;MpThreatOpen&lt;/code&gt;, service-control APIs for stopping security services, token theft (&lt;code&gt;NtDuplicateToken&lt;/code&gt; -&amp;gt; &lt;code&gt;CreateProcessAsUserW&lt;/code&gt;), a keylogger (&lt;code&gt;GetKeyState&lt;/code&gt; polling), GDI+ screenshot capture, clipboard theft, event-log tampering, persistence via Startup and AppCompatFlags.&lt;/p&gt;
&lt;p&gt;And it&amp;rsquo;s not theoretical. The sandbox&amp;rsquo;s Suricata alerts read like the RAT&amp;rsquo;s to-do list being completed in real time:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/anyrun-threats.png&#34; alt=&#34;Suricata: XORed executable loaded -&amp;gt; ProcessKiller CnC init -&amp;gt; SilverFox TCP init -&amp;gt; WinOS4.0 login&#34;&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;Win32/ProcessKiller CnC Initialization&lt;/code&gt;  the AV-killer literally phones home to say it&amp;rsquo;s ready. Then the actual C2 channel: &lt;strong&gt;custom binary TCP&lt;/strong&gt; (length-prefixed frames, port 8888), SilverFox init -&amp;gt; WinOS4.0 login -&amp;gt; encrypted tasking -&amp;gt; keep-alives. The HTTPS from stage 1 was just the delivery boy.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/anyrun-connections.png&#34; alt=&#34;RuntimeBroker.exe -&amp;gt; 103.97.131.179:8888, flagged malicious&#34;&gt;&lt;/p&gt;
&lt;p&gt;Full task is public if you want to poke it yourself: &lt;a href=&#34;https://app.any.run/tasks/f6eeccd8-93e8-4f49-8cc0-f8e815c835b9&#34;&gt;app.any.run/tasks/f6eeccd8-…&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/anyrun-analysis.png&#34; alt=&#34;The full sandbox view: tags, tracker, process tree&#34;&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/thisisfile-malware.jpg&#34; alt=&#34;RuntimeBroker doing crimes while looking like Windows&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;the-platform&#34;&gt;the platform&lt;/h2&gt;
&lt;p&gt;Here is where it went from &amp;ldquo;nice find&amp;rdquo; to &amp;ldquo;oh, this is big.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;I pivoted on the delivery IP (&lt;code&gt;103.23.172.118&lt;/code&gt;) using only passive sources. It is hosting &lt;strong&gt;15 randomized &lt;code&gt;.eu.cc&lt;/code&gt; subdomains&lt;/strong&gt;  &lt;code&gt;kaiwyrey&lt;/code&gt;, &lt;code&gt;isudcnzy&lt;/code&gt;, &lt;code&gt;idutyarwse&lt;/code&gt;, and friends. urlscan has 236 scans against this IP, including &lt;strong&gt;four different lure links scanned TODAY&lt;/strong&gt;, each following the pattern:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;/d/&amp;lt;file-id&amp;gt;/file?code=&amp;lt;32-hex-chars&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Every &lt;code&gt;?code=&lt;/code&gt; is a per victim, one-time download token. Individually tracked targets. One of today&amp;rsquo;s links served &lt;strong&gt;&lt;code&gt;Tax-Number852690.zip&lt;/code&gt;&lt;/strong&gt;  which matches the &lt;code&gt;Tax-Number.zip&lt;/code&gt; ValleyRAT submission sitting in the same ANY.RUN feed. So the GST lure is one plank of a multi-region, multi-lure operation, and it is actively serving victims &lt;em&gt;right now&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Oh, and the server&amp;rsquo;s TLS certificate? Let&amp;rsquo;s Encrypt, issued to &lt;code&gt;bdgsewa.eu.cc&lt;/code&gt;, dated &lt;strong&gt;June 8, 2026&lt;/strong&gt;. The &amp;ldquo;backup&amp;rdquo; domain from the config is the server&amp;rsquo;s actual identity, and this platform was staged a full &lt;strong&gt;two months&lt;/strong&gt; before the GST wave. Infra June 8 -&amp;gt; build Aug 2 -&amp;gt; lure Aug 7 -&amp;gt; still hot Aug 17.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://blog.himanshuanand.com/images/always-has-been-malware.jpg&#34; alt=&#34;it was a delivery platform&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;what-they-actually-want&#34;&gt;what they actually want&lt;/h2&gt;
&lt;p&gt;Code tells you how and targeting tells you why.&lt;/p&gt;
&lt;p&gt;A GSTR-3B lure selects for exactly one population: &lt;strong&gt;Indian accountants, finance teams, CA firms.&lt;/strong&gt; Those machines hold corporate net-banking (used for tax payments), GST-portal creds and  the crown jewel  the email identity that approves payments.&lt;/p&gt;
&lt;p&gt;Silver Fox&amp;rsquo;s documented monetization for finance-staff compromise is &lt;strong&gt;payment-diversion fraud&lt;/strong&gt;: persist quietly (UAC bypass + Defender tampering + AV-killer = long-term silence), watch how payments get approved, then divert them. Espionage grade collection comes free with the implant. The per-victim token links seal it: this is a crew that monetizes &lt;em&gt;specific&lt;/em&gt; finance departments, not bulk infections.&lt;/p&gt;
&lt;p&gt;One line: &lt;strong&gt;quiet, AV-immune, persistent control of Indian corporate finance machines during filing season, monetized through credential theft and payment diversion.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;what-is-new-here&#34;&gt;what is new here&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;#&lt;/th&gt;
&lt;th&gt;Finding&lt;/th&gt;
&lt;th&gt;Before this post&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;td&gt;Silver Fox &lt;strong&gt;GST/GSTR-3B lure wave&lt;/strong&gt; timed to the 20 Aug filing deadline&lt;/td&gt;
&lt;td&gt;Unreported (&lt;a href=&#34;https://www.cloudsek.com/blog/silver-fox-targeting-india-using-tax-themed-phishing-lures&#34;&gt;Dec 2025 was income-tax lures&lt;/a&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;SystemSettings.exe&lt;/code&gt; + patched &lt;code&gt;SystemSettings.dll&lt;/code&gt; sideload pair (sig attached, HashMismatch)&lt;/td&gt;
&lt;td&gt;Undocumented for Silver Fox&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;td&gt;Backup domain &lt;code&gt;bdgsewa.eu.cc&lt;/code&gt; + URI paths&lt;/td&gt;
&lt;td&gt;Zero public references&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;C2s &lt;code&gt;103.97.131.179:6666&lt;/code&gt; and &lt;code&gt;103.97.128.141:7777&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Zero public references&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;Full stage-2 config (build 2026-08-02, group tag 默认)&lt;/td&gt;
&lt;td&gt;First publication&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;UACMe/Akagi + Defender COM tampering + ProcessKiller in this build&lt;/td&gt;
&lt;td&gt;First publication&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;td&gt;The 15-subdomain &lt;code&gt;eu.cc&lt;/code&gt; delivery platform + per-victim &lt;code&gt;?code=&lt;/code&gt; tokens + June-8 cert timeline&lt;/td&gt;
&lt;td&gt;Unmapped&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;All hashes below&lt;/td&gt;
&lt;td&gt;None previously published&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&#34;iocs&#34;&gt;iocs&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Files&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Artifact&lt;/th&gt;
&lt;th&gt;SHA-256 / MD5&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Patched &lt;code&gt;SystemSettings.dll&lt;/code&gt; (stage 1)&lt;/td&gt;
&lt;td&gt;&lt;code&gt;9FA3609CBEA11930BB76DBFD6253A397C10A833CE9DAC19CE55E18501B2F5D10&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lure EXE (signed &lt;code&gt;SystemSettings.exe&lt;/code&gt;, benign-but-abused)&lt;/td&gt;
&lt;td&gt;&lt;code&gt;D3A50D173AF5B0FDD44CBFD7BF7C7471A3B8998EB45C9B49AA2F1C98C9D54CA9&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lure ZIP&lt;/td&gt;
&lt;td&gt;MD5 &lt;code&gt;FE22479CCB81AEC2BC069765484641E5&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Network&lt;/strong&gt; (live at time of writing  &lt;code&gt;103.97.131.179:8888&lt;/code&gt; and &lt;code&gt;:6666&lt;/code&gt; answering)&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;iysdzxc.eu.cc&lt;/code&gt; -&amp;gt; &lt;code&gt;103.23.172.118:443&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;stage-2 delivery&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;bdgsewa.eu.cc&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;backup delivery (dormant-ish)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;/d/ee2b12fbd661&lt;/code&gt;, &lt;code&gt;/d/6c42e162ed46&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;delivery URI paths&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;103.97.131.179:8888&lt;/code&gt; / &lt;code&gt;:6666&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;ValleyRAT C2 (custom TCP)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;103.97.128.141:7777&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;tertiary C2 (not yet up)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;15 &lt;code&gt;.eu.cc&lt;/code&gt; subs: &lt;code&gt;iysdzxc bdgsewa kaiwyrey isudcnzy idutyarwse fuerubuiaie hsaueraw kcjsjyeaw ksidxhcte laiwybstw oaiwuyda oaosifytaw pzidiauwytsd rcyawday xkcisetr zuxyegea&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;delivery platform fronts&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;YARA (stage-1 DLL)&lt;/strong&gt;&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;rule SilverFox_GSTR3B_Patched_SystemSettings_dll
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    meta:
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        description = &amp;#34;Silver Fox ValleyRAT stage-1: patched Microsoft SystemSettings.dll, XOR-0x70 config&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        date = &amp;#34;2026-08-17&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        sha256 = &amp;#34;9FA3609CBEA11930BB76DBFD6253A397C10A833CE9DAC19CE55E18501B2F5D10&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    strings:
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        $name     = &amp;#34;SystemSettings.dll&amp;#34; ascii
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        $ua       = &amp;#34;Edg/131.0.0.0&amp;#34; ascii
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        $xor_c2_1 = { 19 09 03 14 0a 08 13 5e 15 05 5e 13 13 }
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        $xor_c2_2 = { 12 14 17 03 15 07 11 5e 15 05 5e 13 13 }
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        $movabs   = { 48 b8 19 09 03 14 0a 08 13 5e }
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;    condition:
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;        uint16(0) == 0x5A4D and $name and $ua and any of ($xor_c2_*, $movabs)
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Quick wins for your SOC:&lt;/strong&gt; alert on &lt;code&gt;SystemSettings.exe&lt;/code&gt; running from anywhere except &lt;code&gt;%SystemRoot%\ImmersiveControlPanel&lt;/code&gt;; flag Microsoft-named DLLs with HashMismatch signatures; block &lt;code&gt;*.eu.cc&lt;/code&gt; if you can (you can); mail-gateway rule for GSTR/GSTIN + &lt;code&gt;.img&lt;/code&gt;/&lt;code&gt;.iso&lt;/code&gt; attachments during filing windows; hunt RuntimeBroker.exe making outbound TCP to hosting providers. Report to &lt;a href=&#34;https://www.cert-in.org.in/&#34;&gt;CERT-In&lt;/a&gt; if you see hits  I have a full reporting pack ready.&lt;/p&gt;
&lt;h2 id=&#34;final-thoughts&#34;&gt;final thoughts&lt;/h2&gt;
&lt;p&gt;Two things stuck with me from this one.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;One:&lt;/strong&gt; the public sandbox feed is underrated as a hunting ground. This whole campaign  unreported by every vendor  was sitting in ANY.RUN&amp;rsquo;s public submissions with a giant GST-themed name tag on it. The samples, the dumps, the network telemetry: all public. The expensive part was knowing what to pull on the thread.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Two:&lt;/strong&gt; the defense-evasion bar keeps rising in the boring direction. No zero-days here, No novel exploit. Just a signed Microsoft binary, a patched Microsoft DLL, a disk image, and a cloud URL  every individual component &amp;ldquo;trusted&amp;rdquo; by something. The only broken signature in the entire chain still says &amp;ldquo;Microsoft&amp;rdquo; on it. If your detections are still waiting for something that &lt;em&gt;looks&lt;/em&gt; malicious, this is what sails past.&lt;/p&gt;
&lt;p&gt;The GST deadline is the 20th. If you work with Indian finance teams, today is a good day to send them a very boring, very lifesaving email: &lt;em&gt;tax notices don&amp;rsquo;t arrive as disk images.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Stay safe, patch your detections, and remember  RuntimeBroker.exe has no business calling Hong Kong.&lt;/p&gt;
&lt;hr&gt;
</content>
    </item>
    
  </channel>
</rss>
