


Perceptive Security
SOC/SIEM Consultancy

Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
Published:
4 December 2025 at 17:25:00
Alert date:
5 December 2025 at 08:03:22
Source:
thehackernews.com

The threat actor Silver Fox conducted a false flag operation mimicking Russian threat groups to target Chinese organizations. The campaign used SEO poisoning and fake Microsoft Teams installers as lures to distribute ValleyRAT (also known as Winos 4.0) malware. This represents an active malware distribution campaign targeting specific geographic regions through social engineering tactics.
Technical details
Mitigation steps:
Affected products:
Microsoft Teams
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.