A Chinese cybercrime group known as SilverFox has been linked to a new cyberattack targeting a Japanese manufacturing company. Security researchers found that the attackers used an advanced hacking method called Bring Your Own Vulnerable Driver (BYOVD) to bypass Windows security and secretly install ValleyRAT, a remote access trojan that allows attackers to control infected systems. The campaign shows that SilverFox is continuing to improve its attack techniques and malware tools.

The attack begins with a phishing email that pretends to be a business invoice. Victims are tricked into downloading a ZIP file hosted on trusted cloud services, making the file appear safe. Once opened, the archive starts a carefully planned infection chain that downloads additional files and launches legitimate applications in a way that secretly loads malicious code without raising suspicion. This technique helps the malware avoid detection during the early stages of the attack.
One of the biggest changes in this campaign is the use of a three-driver BYOVD framework. Earlier attacks relied on fewer vulnerable drivers, but researchers discovered that SilverFox has now added BootRepair.sys and EnPortv.sys alongside wsftprm.sys. These vulnerable drivers are abused to gain kernel-level access, disable security protections, and make it harder for antivirus software to stop the attack. Using multiple drivers also allows the attackers to replace one driver with another if it becomes blocked.

The malware also takes advantage of DLL sideloading, where trusted applications such as ConvertToPDF.exe and PDFDirect.exe unknowingly load a malicious DLL named PDFCORE8.dll. Inside this DLL are the vulnerable drivers and other components needed for the attack. This approach allows the malware to hide behind legitimate software, making the infection appear normal while secretly preparing the system for the next stage.
To make detection even more difficult, SilverFox removes security monitoring from Windows by using NTDLL unhooking. It also stores parts of the malware in the Windows Registry and injects malicious code into a newly created svchost.exe process. These techniques reduce the chances of endpoint security tools spotting suspicious activity while keeping the malware active in memory.

The final payload delivered during the attack is ValleyRAT, also known as Winos 4.0, a remote access trojan based on the Gh0st RAT family. Once installed, it allows attackers to communicate with the infected computer, execute commands, run additional malware, and perform various post-compromise activities. This gives the attackers long-term remote access and control over the victim’s system.
Researchers also found that the malware includes two separate watchdog mechanisms to ensure it keeps running. One component constantly monitors the malicious payload, while another watchdog script checks whether the malware loader is still active. If either part is removed, the other automatically restores it. This layered recovery system makes the infection much more difficult for defenders to completely eliminate.

According to researchers, this campaign highlights how SilverFox continues to strengthen its malware toolkit with more modular and resilient attack methods. The combination of phishing, vulnerable drivers, DLL sideloading, process injection, and recovery mechanisms creates a highly persistent threat. Organizations should remain alert by keeping systems updated, monitoring suspicious driver activity, and training employees to recognize phishing emails that may deliver sophisticated malware like ValleyRAT.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news