Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silver Fox’s New BYOVD Attack Targets Japanese Industry

Silver Fox’s New BYOVD Attack Targets Japanese Industry

Posted on July 30, 2026 By CWS

The Chinese cybercriminal group known as Silver Fox has launched a sophisticated attack targeting a Japanese company in the industrial manufacturing sector. This operation leverages the Bring Your Own Vulnerable Driver (BYOVD) method, utilizing new drivers to deploy ValleyRAT, also known as Winos 4.0, for persistent remote access. This campaign highlights evolving tactics in cyber threats aimed at undermining industrial targets.

Innovative Attack Techniques

In their latest campaign, Silver Fox combines several advanced techniques, including the abuse of legitimate applications for DLL sideloading and the implementation of a three-driver BYOVD chain. Cato Networks researchers, including Shani Kurtzberg and her team, have provided an in-depth analysis of these methods, which are designed to evade defenses and maintain the operation of ValleyRAT continuously.

The attack initiates with a phishing scheme disguised as an invoice, which utilizes content hosted on legitimate QQ and Tencent Cloud services. This approach facilitates a DLL sideloading chain through a ZIP archive, eventually leading to the deployment of ValleyRAT. Before reaching this stage, the BYOVD technique is employed to gain kernel access, allowing the malware to bypass security measures on the targeted system.

Technical Details of the Attack

The malicious ZIP archive includes a downloader executable that fetches necessary components from an attacker-controlled Tencent Cloud infrastructure. While historically Silver Fox has used vulnerable drivers like “amsdk.sys” and “wsftprm.sys,” their latest operation introduces “BootRepair.sys” and “EnPortv.sys.” These drivers, combined with “PDFCORE8.dll,” form a modular framework that enhances the malware’s resilience across various environments.

This framework is further bolstered by NTDLL unhooking, a technique used to disable security software hooks monitoring Windows API activities. The malware also incorporates process injection and registry-based payload storage to ensure continued execution. A watchdog script, deployed through a DLL loader, maintains persistence by establishing a scheduled task and communicating with an external server to download and inject shellcode.

Implications and Future Prospects

This attack sequence is notable for its dual watchdog design, which ensures the malware’s persistence even if one component is neutralized. This layered approach requires defenders to simultaneously disrupt multiple elements to effectively thwart the intrusion. The comprehensive recovery architecture and modularity observed in the attack underline Silver Fox’s strategic evolution in cyber warfare.

As Silver Fox continues to refine its techniques, reports indicate the development of new tools such as Atlas RAT and RomulusLoader. A recent analysis by a South Korean cybersecurity firm identified 146 unique samples of Atlas RAT, suggesting a significant scale of operation that might indicate commercial development or private distribution. Although links to Silver Fox are currently based on circumstantial evidence, the group’s continued activity poses a growing threat to industries worldwide.

The Hacker News Tags:BYOVD, Cato Networks, cyber attack, Cybersecurity, DLL Sideloading, Japanese industry, Malware, remote access, Silver Fox, ValleyRAT

Post navigation

Previous Post: AtlasRAT Malware Hidden in Fake Flash Installer
Next Post: Analog Devices Reports Cybersecurity Breach

Related Posts

Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage The Hacker News
Fake IT Support Scam Spreads Havoc C2 Framework Fake IT Support Scam Spreads Havoc C2 Framework The Hacker News
1,500+ Minecraft Players Infected by Java Malware Masquerading as Game Mods on GitHub 1,500+ Minecraft Players Infected by Java Malware Masquerading as Game Mods on GitHub The Hacker News
ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs The Hacker News
Critical Marimo RCE Vulnerability Exploited Rapidly Critical Marimo RCE Vulnerability Exploited Rapidly The Hacker News
Critical Flaw in AI Platform Writer Poses Security Risks Critical Flaw in AI Platform Writer Poses Security Risks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Outage Affects Claude AI Users with Overload Errors
  • DataBahn Secures $40M to Enhance Data Management Solutions
  • AI Network Firewalls: Revolutionizing Cybersecurity
  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Outage Affects Claude AI Users with Overload Errors
  • DataBahn Secures $40M to Enhance Data Management Solutions
  • AI Network Firewalls: Revolutionizing Cybersecurity
  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark