
Invoice Phish Drops ValleyRAT via BYOVD Drivers
Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed…
A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The campaign abused legitimate software and cloud services to load a malicious DLL, disable security tools, and establish remote access with ValleyRAT designed to restart itself if interrupted.
The campaign targeting a Japanese industrial manufacturer began with a simple, familiar lure: an invoice-themed phishing email. Once opened, the attack chain used attacker-controlled content hosted on legitimate QQ and Tencent Cloud services, giving the malicious payload a layer of trust that standard email filtering may not catch. From there, attackers abused legitimate executables, ConvertToPDF.exe and PDFDirect.exe, to sideload a malicious DLL named PDFCORE8.dll. This technique lets malware piggyback on trusted, signed software rather than relying on an obviously suspicious file.
Several factors made this attack effective. First, the invoice pretext is a routine part of business communication for finance and procurement staff, making it easy to overlook as a threat. Second, hosting malicious content on well-known consumer and cloud platforms like QQ and Tencent Cloud reduces suspicion, since employees may assume traffic to recognizable domains is safe. Third, the malware employed a modular Bring Your Own Vulnerable Driver (BYOVD) approach with multiple kernel drivers to terminate endpoint security tools, undermining defenses that organizations typically rely on to catch this kind of intrusion.
What sets this campaign apart is its recovery design. The malware used a dual-layer watchdog architecture, with an external watchdog checking every 30 seconds whether the loader is still running and relaunching it if not. A scheduled task also ensured the malware would relaunch on user logon. Command-and-control communication followed, along with shellcode download and injection into a suspended svchost.exe process. This combination of persistence and self-repair makes the malware, ValleyRAT, considerably harder to remove than a typical infection, since simply killing a process or deleting a file is unlikely to fully stop it.
Because this attack chain relies on human decisions early on, such as opening an invoice attachment, the strongest defense is a combination of employee awareness and technical controls. Finance, Accounts Payable, Procurement, and IT Helpdesk staff are natural targets for invoice-themed lures and should be trained to recognize red flags: unsolicited invoices, content hosted outside a vendor's normal domain, and file packages that include executables rather than standard documents. Pairing this awareness with monitoring for DLL sideloading, driver abuse, and unusual scheduled tasks helps close the gap between initial phishing contact and full system compromise.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The intrusion began with an invoice-themed phishing email that used attacker-controlled content hosted on legitimate QQ and Tencent Cloud services.
The malware used a dual-layer watchdog design and a scheduled task to relaunch itself on logon, making it notably harder to disrupt than typical malware deployments.
Attackers abused legitimate executables ConvertToPDF.exe and PDFDirect.exe to sideload a malicious DLL called PDFCORE8.dll.
Finance, Accounts Payable, Procurement, Executive Assistants, IT Helpdesk, and Security Operations teams are the primary targets since the lure is invoice-themed.
You get an email: subject line says "Invoice for review" from a "vendor" you barely recognize. Looks routine, right? Inside the ZIP, instead of a normal PDF, there’s a folder with "ConvertToPDF.exe" and "PDFDirect.exe" pulled from QQ or Tencent Cloud. You run it, it quietly loads a fake PDFCORE8.dll, kills your security tools, and drops ValleyRAT for remote access. Behind the scenes, it phones home to 43.128.26[.]132, injects code into a suspended svchost.exe, and uses multiple kernel drivers plus a dual watchdog so even if you kill it, it just pops back up. Here’s the move: if an "invoice" makes you run software instead of just opening a PDF, stop. Don’t launch it, report the email to security and confirm the invoice with the vendor using a known contact.

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…