ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

SilverFox BYOVD campaign uses multiple drivers to deploy ValleyRAT in Japan

Source headline: SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

The SilverFox cybercrime group is targeting a Japanese industrial manufacturer using a bring-your-own-vulnerable-driver (BYOVD) approach. The intrusion chain relies on abusing vulnerable drivers to execute code and bypass security controls. The campaign then delivers ValleyRAT (also tracked as Winos 4.0) to maintain persistent remote access. This matters because driver abuse can provide powerful system-level execution and evade conventional defenses. Organizations in industrial and manufacturing environments should review endpoint driver integrity and hunt for ValleyRAT-related persistence and remote access indicators.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#malware #persistence #byovd #drivers #valleyrat
Original reporting The Hacker News SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
Open original source