← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Silver Fox Group Uses New 3-Driver BYOVD Chain to Deliver ValleyRAT to Japanese Manufacturer

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Silver Fox group targeted a Japanese manufacturer.
  • New BYOVD chain uses three vulnerable drivers: BootRepair.sys, EnPortv.sys, and wsftprm.sys.
  • Attack delivers ValleyRAT for remote access.
  • Techniques include DLL sideloading, NTDLL unhooking, and layered recovery.

New Attack Chain Identified

The Silver Fox cybercrime group has been observed utilizing a new attack chain involving a three-driver Bring Your Own Vulnerable Driver (BYOVD) technique. This campaign targeted a Japanese organization operating in the industrial manufacturing sector, with the objective of deploying the ValleyRAT (also known as Winos 4.0) remote access trojan.

Technical Details of the Attack

The attack begins with an invoice-themed phishing email that directs victims to attacker-controlled content hosted on legitimate QQ and Tencent Cloud services. This initiates a DLL sideloading process via a ZIP archive. The archive contains a downloader that retrieves further components from Tencent Cloud infrastructure. The BYOVD technique is employed to gain kernel access and disable security controls, thereby evading detection before ValleyRAT is delivered.

While Silver Fox previously used 'amsdk.sys' and 'wsftprm.sys' for BYOVD, this campaign introduces 'BootRepair.sys' and 'EnPortv.sys'. These new drivers, along with 'wsftprm.sys', are embedded within a malicious DLL ('PDFCORE8.dll') sideloaded by legitimate Zeon Corporation binaries ('ConvertToPDF.exe' or 'PDFDirect.exe'), forming a modular three-driver BYOVD framework. This multi-driver approach aims to ensure operational resilience and allows operators to swap drivers as needed.

Defense Evasion and Persistence

Beyond BYOVD, the malware employs NTDLL unhooking to remove user-mode inline hooks placed by endpoint security software, which are used to monitor Windows API activity. The overall attack integrates BYOVD, DLL sideloading, NTDLL unhooking, process injection, registry-based payload storage, and two independent recovery mechanisms to impair security measures and maintain persistence.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 13 stories · Aug 17

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Chinese cybercrime group Silver Fox has deployed a new three-driver Bring Your Own Vulnerable Driver (BYOVD) attack chain against a Japanese industrial manufacturing organization to install ValleyRAT for persistent remote access. This campaign introduces previously unreported vulnerable drivers and combines them with DLL sideloading and defense evasion techniques to maintain control and bypass security controls. The use of multiple drivers enhances the attack's resilience and adaptability across different environments.