Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silver Fox’s New BYOVD Attack Targets Japanese Industry

Silver Fox’s New BYOVD Attack Targets Japanese Industry

Posted on July 30, 2026 By CWS

The Chinese cybercriminal group known as Silver Fox has launched a sophisticated attack targeting a Japanese company in the industrial manufacturing sector. This operation leverages the Bring Your Own Vulnerable Driver (BYOVD) method, utilizing new drivers to deploy ValleyRAT, also known as Winos 4.0, for persistent remote access. This campaign highlights evolving tactics in cyber threats aimed at undermining industrial targets.

Innovative Attack Techniques

In their latest campaign, Silver Fox combines several advanced techniques, including the abuse of legitimate applications for DLL sideloading and the implementation of a three-driver BYOVD chain. Cato Networks researchers, including Shani Kurtzberg and her team, have provided an in-depth analysis of these methods, which are designed to evade defenses and maintain the operation of ValleyRAT continuously.

The attack initiates with a phishing scheme disguised as an invoice, which utilizes content hosted on legitimate QQ and Tencent Cloud services. This approach facilitates a DLL sideloading chain through a ZIP archive, eventually leading to the deployment of ValleyRAT. Before reaching this stage, the BYOVD technique is employed to gain kernel access, allowing the malware to bypass security measures on the targeted system.

Technical Details of the Attack

The malicious ZIP archive includes a downloader executable that fetches necessary components from an attacker-controlled Tencent Cloud infrastructure. While historically Silver Fox has used vulnerable drivers like “amsdk.sys” and “wsftprm.sys,” their latest operation introduces “BootRepair.sys” and “EnPortv.sys.” These drivers, combined with “PDFCORE8.dll,” form a modular framework that enhances the malware’s resilience across various environments.

This framework is further bolstered by NTDLL unhooking, a technique used to disable security software hooks monitoring Windows API activities. The malware also incorporates process injection and registry-based payload storage to ensure continued execution. A watchdog script, deployed through a DLL loader, maintains persistence by establishing a scheduled task and communicating with an external server to download and inject shellcode.

Implications and Future Prospects

This attack sequence is notable for its dual watchdog design, which ensures the malware’s persistence even if one component is neutralized. This layered approach requires defenders to simultaneously disrupt multiple elements to effectively thwart the intrusion. The comprehensive recovery architecture and modularity observed in the attack underline Silver Fox’s strategic evolution in cyber warfare.

As Silver Fox continues to refine its techniques, reports indicate the development of new tools such as Atlas RAT and RomulusLoader. A recent analysis by a South Korean cybersecurity firm identified 146 unique samples of Atlas RAT, suggesting a significant scale of operation that might indicate commercial development or private distribution. Although links to Silver Fox are currently based on circumstantial evidence, the group’s continued activity poses a growing threat to industries worldwide.

The Hacker News Tags:BYOVD, Cato Networks, cyber attack, Cybersecurity, DLL Sideloading, Japanese industry, Malware, remote access, Silver Fox, ValleyRAT

Post navigation

Previous Post: AtlasRAT Malware Hidden in Fake Flash Installer
Next Post: Analog Devices Reports Cybersecurity Breach

Related Posts

Critical Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks and Persistent Access Critical Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks and Persistent Access The Hacker News
Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
China-Linked Cyber Attacks Target South American Telecoms China-Linked Cyber Attacks Target South American Telecoms The Hacker News
U.S. House Bans WhatsApp on Official Devices Over Security and Data Protection Issues U.S. House Bans WhatsApp on Official Devices Over Security and Data Protection Issues The Hacker News
ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation
  • Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts
  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation
  • Microsoft 365 Copilot Vulnerability Exposes Hidden Prompts
  • GitLab Resolves 13 Security Issues Affecting Data and Pipelines
  • Analog Devices Reports Cybersecurity Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark