The point: SilverFox deploys newly discovered vulnerable drivers in BYOVD attacks to gain persistent access to industrial networks.
The Chinese cybercrime group SilverFox has attacked a Japanese industrial organization with a chain of three vulnerable drivers to deploy the remote access trojan ValleyRAT (also Winos 4.0).
The Chinese cybercrime group SilverFox is combining previously unknown vulnerable drivers with BYOVD technology (Bring Your Own Vulnerable Driver) in its current campaign. The attack concept abuses legitimate but security-flawed kernel drivers for privilege escalation and circumvention of security mechanisms.
The target of the attack was a Japanese organization in the industrial manufacturing sector. With this multi-stage attack, SilverFox succeeded in placing the remote access trojan ValleyRAT (also known as Winos 4.0) on the target organization’s systems. ValleyRAT provides attackers with comprehensive remote access capabilities and persistent control over compromised systems.
For CISOs and security teams, this campaign represents a concrete escalation of the threat landscape: BYOVD attacks bypass traditional driver signature controls and are harder to detect than malware-based techniques. The attack demonstrates that Japanese industrial enterprises are also in the target spectrum of established Chinese cybercrime groups. Organizations must increase their visibility at the kernel level and monitor suspicious driver loading activities.
Source: thehackernews.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.