Silver Fox strikes Japanese manufacturing industry with a three-driver BYOVD chain

Silver Fox targets Japanese manufacturing with a 3-driver BYOVD chain to deploy ValleyRAT. Learn about this cyber threat, attack methods, and mitigations.

Silver Fox strikes Japanese manufacturing industry with a three-driver BYOVD chain
Malware

Illustrative image generated with AI

Phishing invoices and abuse of Chinese cloud services

On July 30, 2026, Cato Networks researchers detected a targeted attack against a Japanese manufacturing company, carried out by the Chinese cybercriminal group Silver Fox. The infection started with an invoice-themed phishing campaign: the emails contained links to malicious content hosted on legitimate services such as QQ and Tencent Cloud. The use of trusted cloud platforms made it harder to block inbound traffic. A ZIP archive downloaded by the victim initiated a DLL side-loading chain designed to deliver the ValleyRAT remote access trojan.

Side-loading and previously undocumented kernel drivers

The archive included legitimate executables from Zeon Corporation, specifically ConvertToPDF.exe or PDFDirect.exe, tools for document conversion. Once executed, these files stealthily loaded a malicious DLL named PDFCORE8.dll. Embedded within it were three vulnerable drivers: BootRepair.sys, EnPortv.sys, and wsftprm.sys. While wsftprm.sys was already known for malicious use, the other two are entirely new to BYOVD campaigns. The Bring Your Own Vulnerable Driver technique allows an attacker to load a signed but vulnerable driver to gain kernel-level privileges and disable security controls. The malware also performs NTDLL unhooking to remove user-mode hooks from security products, increasing stealth.

Dual watchdog and tamper-proof persistence

To maintain access to the compromised environment, the attackers implemented a dual watchdog mechanism. On one hand, an external batch script is scheduled as a system task; on the other, an internal routine within the malware constantly monitors the infection status. The two components watch over each other: if one is terminated, the other immediately restarts it. This architecture makes disinfection particularly challenging, as it requires neutralizing both the loader and the watchdog script simultaneously, as well as disabling the related scheduled tasks.

ValleyRAT, Atlas RAT, and an expanding arsenal

The final payload, ValleyRAT (also known as Winos 4.0), is injected into a legitimate svchost.exe process via thread-context hijacking. The shellcode needed for injection is retrieved from the command-and-control server at 43.128.26[.]132. ValleyRAT provides attackers with full remote access and the ability to exfiltrate data. In parallel, Silver Fox's arsenal is expanding: researchers have identified samples of Atlas RAT, RomulusLoader, and SilentRunLoader. For Atlas RAT, 146 unique samples have been analyzed, a number that suggests commercial-scale development or widespread distribution, although the direct link to Silver Fox remains circumstantial for now.

Mitigations and countermeasures

To defend against such attacks, it is essential to enable Microsoft's vulnerable driver blocklist or implement WDAC policies to prevent the loading of unauthorized drivers. Security teams should monitor for anomalous behaviours, such as Zeon processes loading DLLs from unusual paths, modifications to NTDLL, or the creation of svchost.exe processes by suspicious executables. Limiting script execution from writable folders and applying application whitelisting reduces the attack surface. At the network level, blocking traffic to known IPs such as 43.128.26.132 and filtering access to unauthorized cloud services can contain the spread. Finally, user training remains essential to recognize phishing emails that leverage popular cloud services.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →