importantSYS.SOURCE: The Hacker News• 2026-07-30T16:02:59+05:30
SilverFox Cybercrime Group Exploits BYOVD Technique to Deploy ValleyRAT in Japanese Manufacturing Sector
SilverFox cybercrime group deployed a multi-driver BYOVD attack chain to deliver ValleyRAT malware targeting a Japanese industrial manufacturer. The attack uses DLL sideloading, kernel-level driver exploitation, and dual watchdog mechanisms for persistence and evasion.
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access.
"In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
*** END OF TRANSMISSION ***