<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7" -->

---
title: SilverFox Hackers Use Go RAT, AV Killer, and Kernel...
description: Gen Threat Labs has identified an active SilverFox campaign deploying ValleyRAT through an eight-stage infection chain targeting Windows systems. The attack...
canonical: https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign | daily.dev
og:description: Gen Threat Labs has identified an active SilverFox campaign deploying ValleyRAT through an eight-stage infection chain targeting Windows systems. The attack...
og:url: https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7
og:image: https://api.daily.dev/og/posts/8MNjMf0S7.png
og:image:alt: SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 4 min read · 0 upvotes · 0 comments

## Summary

Gen Threat Labs has identified an active SilverFox campaign deploying ValleyRAT through an eight-stage infection chain targeting Windows systems. The attack begins with DLL side-loading via trojanized installers, uses steganography to hide payloads in PNG images, and employs the Donut loader for in-memory shellcode execution. A Go-based RAT communicates over WebSocket and QUIC, injects an AV-killer into svchost, and ultimately installs a kernel-level rootkit supporting over 65 command codes. The malware also steals cryptocurrency wallet addresses via clipboard hijacking, targets Telegram data, and uses polymorphic recompilation with daily file path rotation to evade static detection. CISOs are advised to monitor for DLL side-loading, hunt post-exploitation patterns like unusual named pipes and QUIC traffic, and treat confirmed rootkit infections as high-severity events requiring full reimaging.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/07/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign>

## Similar posts on daily.dev

- [Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits](https://daily.dev/posts/cracking-valleyrat-from-builder-secrets-to-kernel-rootkits-4spc0feog) · Check Point Research · 0 upvotes · 0 comments
- [Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China](https://daily.dev/posts/silver-fox-uses-fake-microsoft-teams-installer-to-spread-valleyrat-malware-in-china-odxv7rs2i) · The Hacker News · 0 upvotes · 0 comments
- [Fake Huorong security site infects users with ValleyRAT](https://daily.dev/posts/fake-huorong-security-site-infects-users-with-valleyrat-wjalu7j3l) · Security Boulevard · 1 upvotes · 0 comments
- [Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware](https://daily.dev/posts/silver-fox-targets-indian-users-with-tax-themed-emails-delivering-valleyrat-malware-v73lloqab) · The Hacker News · 0 upvotes · 0 comments
- [ValleyRAT is spreading disguised as adware](https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl) · Securelist · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign","url":"https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7"},"datePublished":"2026-07-07T10:49:54.956Z","dateModified":"2026-07-07T10:50:22.953Z","description":"Gen Threat Labs has identified an active SilverFox campaign deploying ValleyRAT through an eight-stage infection chain targeting Windows systems. The attack...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign"}]}
```

