Executive Summary
Malware campaigns are currently targeting Chinese-speaking users through fake software installers, specifically impersonating LINE, LetsVPN, and remote-desktop applications. These installers utilize NSIS and often carry invalid or tampered digital certificates issued to "Chengdu MODIFENGNIAO Network Technology Co., Ltd." Once executed, the malware employs sophisticated evasion techniques, including excluding drives from Windows Defender scanning and using "PoolParty Variant 7" to inject code into standard Windows processes like Explorer.exe and UserAccountBroker.exe.
The attack chain involves multiple shellcode files (config.ini, config2.ini, and Sangee.ini) and creates watchdogs to ensure persistence and payload delivery. While some persistence mechanisms via Scheduled Tasks appear incomplete in recent samples, the malware successfully communicates with command-and-control servers to download further payloads, likely ValleyRat. There is evidence of specific targeting of security products from Qihoo 360 Technology, with code designed to disrupt their TCP connections. The overall trend indicates an evolution toward stealthier injection methods and enhanced anti-analysis capabilities to bypass sandbox environments.
Facts Only
* Cybereason detected malware disguised as software installers since the beginning of 2025.
* Targets include Chinese-speaking users.
* Impersonated software includes LINE, LetsVPN, ToDesk, AnyDesk, and Sogou.
* Malware is built using the Nullsoft Scriptable Install System (NSIS).
* Digital certificates are issued to "Chengdu MODIFENGNIAO Network Technology Co., Ltd."
* The malware uses the "PoolParty Variant 7" injection technique to target Explorer.exe.
* It interacts with C2 servers at 143.92.38[.]217:18852 and 206.238.221[.]165:443.
* PowerShell commands are used to exclude drives C through F from Windows Defender scanning.
* The malware attempts to disrupt TCP connections for 360 Total Security processes.
* Downloaded payloads are identified as likely being ValleyRat (Winos 4.0).
* Associated threat group is believed to be Silver Fox APT.
Full Take
The strongest version of this narrative is a highly technical forensic breakdown of a targeted APT campaign, providing specific IOCs and behavioral patterns to help defenders mitigate a real-world threat. It correctly identifies a trend of shifting from noisy batch files to stealthy process injection.
However, the delivery follows a classic vendor-intelligence loop: a high-detail technical analysis of a threat is used as the load-bearing evidence to validate the efficacy of the vendor's own detection capabilities. By framing the threat through the lens of "detection and prevention," the technical data serves as a proxy for a product pitch.
Patterns detected: ARC-0064 Authority Game, ARC-0012 Fear Appeal
The driving paradigm is the "Arms Race" narrative—the idea that as attackers evolve (e.g., moving to PoolParty Variant 7), only specialized, high-end security services can maintain visibility. The unstated assumption is that standard OS defenses are insufficient and that behavioral EDR is the only viable shield. This benefits the security industry by creating a perpetual need for updated, paid detection logic.
This reflects a broader trend where "Threat Intel" becomes a marketing channel. The cost is borne by the user, who is conditioned to feel a sense of helplessness against "APT" groups, shifting agency away from basic security hygiene toward reliance on proprietary black-box solutions.
Bridge Questions:
1. If the persistence scripts are "incomplete," does this suggest a lack of sophistication by the actor or a deliberate attempt to mislead analysts?
2. How many "APT" attributions are based on shared code libraries (like sRDI) rather than unique actor signatures?
Counterstrike Scan: A coordinated campaign would use a high-profile "new threat" to drive urgent procurement of a specific security tool. While the technical data here is substantive, the structural alignment with a vendor-led acquisition funnel is present.
From the original · Cyberreason Blog
Cybereason Detects and Prevents 3CXDesktopApp Supply Chain Attack Cybereason detects and prevents the ongoing 3CXDesktopApp supply chain attack. Cybereason Security Services Team Cybereason Security Services issue Threat Analysis reports to inform on impacting threats.Read the full story at cybereason.com
