Threat Intelligence

Silver Fox group uses new drivers in BYOVD attacks against Japanese manufacturer

Laptop Screen Warning Alert: Cyber Attack, Virus, Malware, Spyware, System Hacked

A Chinese cybercrime group known as Silver Fox has been observed employing new drivers in bring your own vulnerable driver (BYOVD) attacks against a Japanese organization in the industrial manufacturing sector, according to Cato Networks researchers. The ultimate goal of these attacks is to deploy ValleyRAT, also known as Winos 4.0, for persistent remote access, based on information published by The Hacker News.

The attack chain begins with a phishing lure disguised as an invoice, utilizing attacker-controlled content hosted on legitimate QQ and Tencent Cloud services. This triggers a DLL side-loading chain via a ZIP archive, which then deploys ValleyRAT. Before deployment, the BYOVD technique is used to gain kernel access and disable security controls, aiding in evasion. The group has previously used vulnerable drivers like "amsdk.sys" and "wsftprm.sys," but this campaign introduces "BootRepair.sys" and "EnPortv.sys." These drivers, embedded within a malicious DLL, form a modular BYOVD framework for defense evasion.

The malware also employs NTDLL unhooking to bypass endpoint security software. A dual watchdog design ensures persistence by monitoring both the injected payload and the loader, making it difficult for defenders to neutralize the intrusion. This layered approach enhances resilience and modularity. Silver Fox continues to develop new tools and techniques, recently observed using tax-themed lures to deliver other RATs.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds