A Chinese cybercrime group known as Silver Fox has been observed employing new drivers in bring your own vulnerable driver (BYOVD) attacks against a Japanese organization in the industrial manufacturing sector, according to Cato Networks researchers. The ultimate goal of these attacks is to deploy ValleyRAT, also known as Winos 4.0, for persistent remote access, based on information published by The Hacker News.The attack chain begins with a phishing lure disguised as an invoice, utilizing attacker-controlled content hosted on legitimate QQ and Tencent Cloud services. This triggers a DLL side-loading chain via a ZIP archive, which then deploys ValleyRAT. Before deployment, the BYOVD technique is used to gain kernel access and disable security controls, aiding in evasion. The group has previously used vulnerable drivers like "amsdk.sys" and "wsftprm.sys," but this campaign introduces "BootRepair.sys" and "EnPortv.sys." These drivers, embedded within a malicious DLL, form a modular BYOVD framework for defense evasion.The malware also employs NTDLL unhooking to bypass endpoint security software. A dual watchdog design ensures persistence by monitoring both the injected payload and the loader, making it difficult for defenders to neutralize the intrusion. This layered approach enhances resilience and modularity. Silver Fox continues to develop new tools and techniques, recently observed using tax-themed lures to deliver other RATs.Source: The Hacker News
Threat Intelligence
Silver Fox group uses new drivers in BYOVD attacks against Japanese manufacturer

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



