The Chinese cybercriminal group known as Silver Fox has launched a sophisticated attack targeting a Japanese company in the industrial manufacturing sector. This operation leverages the Bring Your Own Vulnerable Driver (BYOVD) method, utilizing new drivers to deploy ValleyRAT, also known as Winos 4.0, for persistent remote access. This campaign highlights evolving tactics in cyber threats aimed at undermining industrial targets.
Innovative Attack Techniques
In their latest campaign, Silver Fox combines several advanced techniques, including the abuse of legitimate applications for DLL sideloading and the implementation of a three-driver BYOVD chain. Cato Networks researchers, including Shani Kurtzberg and her team, have provided an in-depth analysis of these methods, which are designed to evade defenses and maintain the operation of ValleyRAT continuously.
The attack initiates with a phishing scheme disguised as an invoice, which utilizes content hosted on legitimate QQ and Tencent Cloud services. This approach facilitates a DLL sideloading chain through a ZIP archive, eventually leading to the deployment of ValleyRAT. Before reaching this stage, the BYOVD technique is employed to gain kernel access, allowing the malware to bypass security measures on the targeted system.
Technical Details of the Attack
The malicious ZIP archive includes a downloader executable that fetches necessary components from an attacker-controlled Tencent Cloud infrastructure. While historically Silver Fox has used vulnerable drivers like “amsdk.sys” and “wsftprm.sys,” their latest operation introduces “BootRepair.sys” and “EnPortv.sys.” These drivers, combined with “PDFCORE8.dll,” form a modular framework that enhances the malware’s resilience across various environments.
This framework is further bolstered by NTDLL unhooking, a technique used to disable security software hooks monitoring Windows API activities. The malware also incorporates process injection and registry-based payload storage to ensure continued execution. A watchdog script, deployed through a DLL loader, maintains persistence by establishing a scheduled task and communicating with an external server to download and inject shellcode.
Implications and Future Prospects
This attack sequence is notable for its dual watchdog design, which ensures the malware’s persistence even if one component is neutralized. This layered approach requires defenders to simultaneously disrupt multiple elements to effectively thwart the intrusion. The comprehensive recovery architecture and modularity observed in the attack underline Silver Fox’s strategic evolution in cyber warfare.
As Silver Fox continues to refine its techniques, reports indicate the development of new tools such as Atlas RAT and RomulusLoader. A recent analysis by a South Korean cybersecurity firm identified 146 unique samples of Atlas RAT, suggesting a significant scale of operation that might indicate commercial development or private distribution. Although links to Silver Fox are currently based on circumstantial evidence, the group’s continued activity poses a growing threat to industries worldwide.
