Security1 publisher3 min readPublished
Silver Fox times ValleyRAT to India's GST deadline behind a real Microsoft signature
A researcher says an unreported campaign used a fake GSTR-3B overdue notice ahead of the 20 August filing deadline, delivering a patched DLL that a genuinely signed Microsoft binary loads.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
.png)
What happened
- An unreported Silver Fox campaign served ValleyRAT to Indian taxpayers with a fake 'GSTR-3B overdue' lure, timed to the real 20 August GST filing deadline. Delivery was a disk image containing a genuinely Microsoft-signed SystemSettings.exe that sideloads a patched SystemSettings.dll.
- The file GST_Filing_Overdue_GSTR-3B_GSTIN27ABCDE1234F1Z5_Due_20082026.zip was submitted to ANY.RUN's public submissions on 7 August 2026.
- The ZIP contains a 1.2 MB .img disk image; files inside a mounted image do not inherit Mark-of-the-Web, so the 'this came from the internet' prompts never fire, and the image mounts on double click like a USB drive.
- Inside the disk image are two files: GST_Filing_Overdue_GSTR-3B_..._Due_20082026.exe at 98 KB and SystemSettings.dll at 59 KB.
- The EXE has a VALID Microsoft Corporation signature and an OriginalFilename of SystemSettings.exe: it is the real Windows Settings app, renamed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Independent researcher Himanshu Anand says he found an unreported Silver Fox campaign delivering the ValleyRAT backdoor to Indian taxpayers using a fake "GSTR-3B overdue" notice timed to the real 20 August GST filing deadline [1]. The delivery chain leans on a genuinely Microsoft-signed copy of SystemSettings.exe that sideloads a patched SystemSettings.dll, which still carries a Microsoft certificate that no longer validates [1][6].
The sample surfaced in ANY.RUN's public submissions on 7 August 2026, named GST_Filing_Overdue_GSTR-3B_GSTIN27ABCDE1234F1Z5_Due_20082026.zip [2]. GSTR-3B is the monthly return every GST-registered business in India files, GSTIN is the tax identifier, the 20th is the actual deadline, and per Anand the GSTIN in the filename uses the correct format, with the 27 prefix corresponding to Maharashtra [14]. The recovered config carries a build date of 2 August 2026 [9], which puts construction 18 days before the deadline it references [1] and public sighting 13 days before it [2].
The ZIP holds a 1.2 MB disk image, which Anand notes matters because files inside a mounted image do not inherit Mark-of-the-Web, so the "this came from the internet" prompts never fire [3]. Inside are two files: a 98 KB executable and a 59 KB SystemSettings.dll [4]. The executable is the real Windows Settings app, renamed, with a valid Microsoft Corporation signature [5]. The DLL was a real Microsoft binary until it was patched; the certificate is still attached but the hash mismatches [6]. Anand's point is the operational one: no unsigned attacker code ever touches disk, and stage one lives entirely inside a tampered system DLL that a signed Microsoft process loads voluntarily [7]. To a reputation-based filter, both files read as Microsoft [6].
The evasion continues inside the DLL. DllMain is stock CRT boilerplate and the exports are stubs, with the implant grafted into the CRT init path, so scanners keying on entry-point anomalies find nothing [15]. The orchestrator function never handles a readable string: API names, C2 addresses and paths are built as stack constants, decoded in place, used and zeroed, with junk calls interleaved [16]. The decoder is a single-byte XOR against 0x70, and the first decoded block resolves kernel32.dll and GetModuleHandleA [17]. Stage two injects into RuntimeBroker.exe carrying a full UACMe kit, a Defender tamperer and an AV process-killer [8]. ANY.RUN flagged the file as malicious with ValleyRAT, silverfox, winos and processkiller tags [10].
None of this is new behaviour for the group. Silver Fox, also tracked as SwimSnake and Void Arachne, is a China-nexus crew running ValleyRAT on the WinOS 4.0 framework, a plugin-based RAT with keylogging and screen capture [12]. Anand cites CloudSEK research on Income Tax Department lures aimed at Indian users since at least December 2025, NCC Group on SEO-poisoned fake installers, and a Russian false-flag operation intended to confuse attribution [13]. Sideloading behind signed binaries, disposable free-domain C2 and tax-season timing are described as the group's standard fare [19].
What to watch: the config includes three C2 endpoints, a dormant backup domain, and a 15-subdomain delivery platform issuing per-victim lure links, which means takedowns of one domain buy little [9]. Anand reports zero public coverage of the file, its C2s or the GST wave beyond a single urlscan record of the delivery domain [11], and his analysis was done on an ANY.RUN account provided under a collaboration [18]. The transferable lesson for defenders is scheduling: filing deadlines are published, so the weeks before the 20th of any month are a predictable window for lures that arrive wearing a valid signature.