The Silver Fox cybercrime group has been observed utilizing a new attack chain involving a three-driver Bring Your Own Vulnerable Driver (BYOVD) technique. This campaign targeted a Japanese organization operating in the industrial manufacturing sector, with the objective of deploying the ValleyRAT (also known as Winos 4.0) remote access trojan.
The attack begins with an invoice-themed phishing email that directs victims to attacker-controlled content hosted on legitimate QQ and Tencent Cloud services. This initiates a DLL sideloading process via a ZIP archive. The archive contains a downloader that retrieves further components from Tencent Cloud infrastructure. The BYOVD technique is employed to gain kernel access and disable security controls, thereby evading detection before ValleyRAT is delivered.
While Silver Fox previously used 'amsdk.sys' and 'wsftprm.sys' for BYOVD, this campaign introduces 'BootRepair.sys' and 'EnPortv.sys'. These new drivers, along with 'wsftprm.sys', are embedded within a malicious DLL ('PDFCORE8.dll') sideloaded by legitimate Zeon Corporation binaries ('ConvertToPDF.exe' or 'PDFDirect.exe'), forming a modular three-driver BYOVD framework. This multi-driver approach aims to ensure operational resilience and allows operators to swap drivers as needed.
Beyond BYOVD, the malware employs NTDLL unhooking to remove user-mode inline hooks placed by endpoint security software, which are used to monitor Windows API activity. The overall attack integrates BYOVD, DLL sideloading, NTDLL unhooking, process injection, registry-based payload storage, and two independent recovery mechanisms to impair security measures and maintain persistence.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Chinese cybercrime group Silver Fox has deployed a new three-driver Bring Your Own Vulnerable Driver (BYOVD) attack chain against a Japanese industrial manufacturing organization to install ValleyRAT for persistent remote access. This campaign introduces previously unreported vulnerable drivers and combines them with DLL sideloading and defense evasion techniques to maintain control and bypass security controls. The use of multiple drivers enhances the attack's resilience and adaptability across different environments.