A new Silver Fox-linked campaign is targeting Malaysian users through WhatsApp. It uses a validly signed KuGou executable to load a malicious DLL that pretends to be a Microsoft component. Pelagosx researchers documented the chain on September 27, 2026.
Victims receive a finance-themed message asking them to forward a report for verification and to open the attachment on a computer. The attachment, PDF_C2841_20260911100446.zip, looks like a document but contains an IMG disk image. Inside are two native files: a signed executable and an unsigned DLL.
The executable, PDF_C2089_20260911100446.exe, is signed by Guangzhou Kugou Technology Co., Ltd. Windows reports the signature as valid. Its metadata identifies it as active_desktop_launcher.exe, KuGou version 1.0.0.50.
SilverFox Malware Hides in Signed KuGou App
The companion, active_desktop_render_x64.dll, presents itself as a “Desktop Window Manager Helper” with the original filename dwmapi.dll. It is unsigned.

| File | SHA-256 | Size |
|---|---|---|
| PDF_C2089_20260911100446.exe | F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D | 102,536 bytes |
| active_desktop_render_x64.dll | C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F | 5,242,880 bytes |
Ghidra decompilation shows the launcher simply calls two DLL exports, SetDesktopMonitorHook() and ClearDesktopMonitorHook(). The first enters an obfuscated routine, FUN_180001ae4(). That routine resolves APIs through hash-like identifiers and decodes stack data with XOR. It then transforms a 0x2bc0-byte (11,200-byte) buffer and copies it into executable memory.
At runtime, Pelagosx captured an 11,200-byte buffer after a successful BCryptDecrypt call. The size matches the static finding. The decrypted data held the marker @@RAPID_CFG_START@@, the IP 134.122.155.135, port 443 and the string 默认分组 (“Default group”).

A PDB path, D:\buildbot\build1\desktop_screen\build\bin\active_desktop_launcher_x64.pdb, offers a useful clustering clue.
Both files are copied to %APPDATA%\Microsoft\Update. A Run-key value named MicrosoftUpdate is then written under HKCU\Software\Microsoft\Windows\CurrentVersion\Run (MITRE ATT&CK T1547.001).
The malware then repeatedly tries to reach 134.122.155.135:443. Pelagosx logged 96 connection attempts about three seconds apart.
Pelagosx cautions that no single string, PDB path or persistence trick proves attribution. The assessment rests on the combined behavior: a signed identity, a side-loaded DLL, obfuscated unpacking, Run-key persistence and regular direct-IP callbacks.
CloudSEK separately documented a Silver Fox campaign against India. It delivered ValleyRAT using Xunlei’s signed Thunder.exe with a malicious libexpat.dll. The two share tradecraft, but Pelagosx says they are not an exact campaign match.
Mitigation
Defenders should:
- Alert on Run-key writes pointing to %APPDATA%\Microsoft\Update.
- Hunt for the two staged filenames.
- Block or monitor traffic to 134.122.155.135:443, and look for a roughly three-second beacon rhythm.
- Search for these strings: SetDesktopMonitorHook, ClearDesktopMonitorHook, ReleaseFromExplorer, _ipcfr_wqkqzk, @@RAPID_CFG_START@@ and the buildbot PDB fragment.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.