SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group Silver Fox is targeting Japanese manufacturers using a sophisticated Bring Your Own Vulnerable Driver (BYOVD) attack chain to deploy ValleyRAT, a Gh0st RAT variant. They utilize a layered approach incorporating new drivers – BootRepair.sys, EnPortv.sys, and wsftprm.sys – alongside DLL side-loading and NTDLL unhooking to evade detection and maintain persistent remote access. The attack leverages a dual-watchdog recovery mechanism to ensure continued execution even if individual components are terminated, and the group continues to expand its arsenal with tools like Atlas RAT.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
