← Back to Feed
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
July 30, 2026 · The Hacker News · Severity: MEDIUM
The Chinese cybercrime group Silver Fox targeted a Japanese industrial manufacturing organization using a BYOVD (bring your own vulnerable driver) attack chain involving three drivers, combined with DLL sideloading via legitimate applications, to deploy ValleyRAT (Winos 4.0) for persistent remote access. The attack chain begins with an invoice-themed phishing lure hosted on legitimate QQ and Tencent Cloud services, uses a ZIP archive containing a downloader, and leverages kernel access through vulnerable drivers to impair security controls and evade detection.
Key Takeaways
- Silver Fox used a three-driver BYOVD chain to obtain kernel access and disable security controls on industrial manufacturing targets in Japan.
- The attack chain combines phishing lures on legitimate cloud services (QQ, Tencent Cloud), DLL sideloading, and layered recovery mechanisms to maintain ValleyRAT persistence.
- Defenders should monitor for driver abuse and suspicious DLL sideloading originating from trusted cloud storage platforms.