Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

SilverFox Unveils Sophisticated BYOVD Campaign Targeting Japanese Manufacturer


SilverFox Unveils Sophisticated BYOVD Campaign Targeting Japanese Manufacturer
A Chinese cybercrime group known as Silver Fox has been observed employing innovative tactics to compromise a Japanese manufacturer in the industrial manufacturing sector. The attack involved the use of a three-driver bring your own vulnerable driver (BYOVD) chain and ValleyRAT, demonstrating the group's cunning approach to cybercrime.

  • The Chinese cybercrime group Silver Fox has compromised a Japanese manufacturer using innovative tactics.
  • The attack involved the use of a three-driver bring your own vulnerable driver (BYOVD) chain and ValleyRAT, showcasing sophisticated threats.
  • Silver Fox leveraged legitimate software binaries to obtain kernel access, evading detection by traditional security measures.
  • The group's modular BYOVD framework allows for operational resilience and defense evasion.
  • The malware utilizes NTDLL unhooking, DLL loader, and scheduled tasks for persistence and communication with an external server.
  • The final-stage implant is ValleyRAT, offering remote-access functionality and command-and-control communication.
  • Silver Fox continues to refine its arsenal with new tools, highlighting the importance of adapting security measures.


  • In a recent development that underscores the evolving threat landscape, a Chinese cybercrime group known as Silver Fox has been observed employing innovative tactics to compromise a Japanese manufacturer in the industrial manufacturing sector. The attack, which involved the use of a three-driver bring your own vulnerable driver (BYOVD) chain and ValleyRAT, is a testament to the sophistication and adaptability of modern-day threats.

    The campaign, which began with an invoice-themed phishing lure hosted on legitimate QQ and Tencent Cloud services, serves as a paradigm for the group's cunning approach to cybercrime. The attackers cleverly leveraged the BYOVD technique to obtain kernel access and impair security controls on the compromised host, evading detection in the process. This tactic allows the attackers to sidestep traditional security measures, effectively nullifying the efficacy of many modern security solutions.

    At the heart of this campaign lies a modular three-driver BYOVD framework, comprising "BootRepair.sys," "EnPortv.sys," and "wsftprm.sys" drivers. These legitimate binaries are associated with Zeon Corporation, a Japanese software company that provides various applications for Windows operating systems. The malicious DLL ("PDFCORE8.dll") embedded with these drivers embeds the aforementioned drivers, turning the malware into a sophisticated modular framework for defense evasion.

    This modular approach to BYOVD implementation allows Silver Fox to ensure operational resilience across environments and provides them with the ability to swap out drivers and replace them with other options while maintaining the integrity of their workflow. This level of sophistication underscores the group's commitment to using the most advanced techniques in order to achieve their goals.

    Furthermore, the malware utilizes NTDLL unhooking to remove user-mode inline hooks placed by endpoint security software, effectively keeping tabs on native Windows API activity. The DLL loader acts as a self-contained execution framework, unleashing a watchdog batch script that ensures persistence by means of a scheduled task and communicates with an external server ("43.128.26[.]132") to fetch shellcode injected into a new "svchost.exe" process using thread-context hijacking.

    The resulting final-stage implant is ValleyRAT, a variant of Gh0st RAT offering remote-access functionality, including command-and-control (C2) communication, task execution, and additional post-compromise capabilities. The attack sequence is notable for its dual watchdog design that ensures execution recovery. This two-pronged approach means that terminating one component alone may not completely neutralize the intrusion, as it allows either component to spring into action in order to relaunch the other stage.

    The disclosure of this campaign comes at a time when Silver Fox continues to refine and expand its arsenal with new tools such as Atlas RAT (aka AtlasCross RAT), RomulusLoader, and SilentRunLoader. The group's use of tax-themed lures to deliver Gh0st RAT and DCRat further highlights their adaptability and willingness to evolve in order to achieve their objectives.

    In conclusion, the recent campaign by Silver Fox serves as a stark reminder of the evolving threat landscape and the importance of staying vigilant against modern-day threats. As threat actors continue to refine and expand their arsenal, it is essential that security measures are adapted accordingly in order to remain effective.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/SilverFox-Unveils-Sophisticated-BYOVD-Campaign-Targeting-Japanese-Manufacturer-ehn.shtml

  • https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html


  • Published: Thu Jul 30 07:38:53 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us