The Chinese cybercrime group Silver Fox has launched a sophisticated attack on a Japanese industrial manufacturer, leveraging a bring your own vulnerable driver BYOVD methodology to deliver ValleyRAT malware for persistent remote access. This campaign uniquely combines the use of three different vulnerable drivers, namely BootRepair.sys, EnPortv.sys, and wsftprm.sys, to bypass security measures and ensure operational resilience. The attack commences with a phishing strategy centered around an invoice theme, using QQ and Tencent Cloud services to initiate a DLL side-loading chain. This chain ultimately leads to the deployment of ValleyRAT, with the initial phases employing BYOVD techniques to gain kernel access and disable security controls.

In the execution framework, a ZIP archive contains a downloader that retrieves components for DLL side-loading from Tencent Cloud, enabling further stages of the attack. The use of multiple drivers in the BYOVD framework allows Silver Fox to maintain flexibility and adaptability in their attack strategy. Additionally, the malware employs advanced techniques such as NTDLL unhooking, process injection, and registry-based payload storage to evade detection and maintain persistence. A dual watchdog design further ensures the malware's resilience, with a scheduled task and a watchdog script both playing roles in reestablishing components if disrupted.

Silver Fox's ongoing expansion of its toolkit, including the introduction of new tools like Atlas RAT, RomulusLoader, and SilentRunLoader, highlights the group's commitment to refining their capabilities. A recent report from a South Korean cybersecurity firm identified 146 unique samples of Atlas RAT, suggesting the possibility of commercial development or private distribution. While links to Silver Fox are based on circumstantial evidence, the group's evolving tactics pose a significant challenge to cybersecurity defenses worldwide.