Campaign KCPhoenix: Inside Silver Fox’s latest ValleyRAT chain
Report summary
The Silver Fox threat actor continues to refine its delivery and evasion techniques. Following our July 2026 research, in newly identified activity tracked by the Atos Threat Research Center as Campaign KCPhoenix, the group deploys ValleyRAT through a trojanized AnyDesk installer while introducing several notable enhancements designed to weaken endpoint visibility and resist analysis. The campaign combines trusted software abuse, in-memory execution, Windows Security Center manipulation, and a Bring Your Own Vulnerable Driver (BYOVD) technique to maintain access while reducing the likelihood of detection.
Our research reveals a multi-stage infection chain that goes beyond previously documented Silver Fox activity. Among the most significant findings are the use of a vulnerable kernel driver to disable security processes, a fake antivirus registration that keeps Windows reporting the system as protected, and a customised Donut-based loader employing Chaskey encryption to conceal the final payload.
The final stage delivers ValleyRAT, a remote access trojan that communicates using KCP over UDP and supports command execution, persistence, and further payload deployment. Throughout the chain, the attackers demonstrate a consistent focus on blending malicious activity with legitimate components, including signed software and trusted system processes.
In the full report, we analyse each stage of the campaign, examine the techniques used to evade security controls, map observed behaviours to MITRE ATT&CK, and provide indicators and detection opportunities to help defenders identify similar activity in their environments.

Full execution chain of campaign KCPhoenix



