news.mlab.sh
Back to the feed
threat-intel

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

High
Image: The Hacker News
Summary

The Chinese cybercrime group Silver Fox is targeting Japanese manufacturers using a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack chain to deploy ValleyRAT, a Gh0st RAT variant. They utilize a layered approach incorporating new drivers – BootRepair.sys, EnPortv.sys, and wsftprm.sys – alongside DLL side-loading and NTDLL unhooking to evade detection and maintain persistent remote access. The attack leverages a dual-watchdog recovery mechanism to ensure continued execution even if individual components are terminated, and the group continues to expand its arsenal with tools like Atlas RAT.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.