Skip to content
feed: live
>_ 0dayNews
threat intel

Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign

Silver Fox combined three vulnerable drivers in a BYOVD chain against a Japanese manufacturer, delivering ValleyRAT (Winos 4.0) for persistent access.

Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign
Photo: Mass Communication Specialist 3rd Class Noel Danseco / Wikimedia Commons · Public domain
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

The Hacker News reports that Silver Fox — a Chinese cybercrime group — has been observed running a BYOVD (bring your own vulnerable driver) campaign against an industrial manufacturing organization in Japan, chaining three vulnerable drivers to deliver ValleyRAT, also tracked as Winos 4.0, for persistent remote access.

Three drivers, not one. That detail matters.

Microsoft’s Vulnerable Driver Blocklist and HVCI (Memory Integrity) enforcement have been tightening the window on single-driver BYOVD attacks. Adding drivers to the blocklist takes time; cycling through three raises the probability that at least one bypasses whatever defensive layer the target has deployed. It’s also an error-correction approach: if the first driver is blocked or absent in the target environment, the chain doesn’t collapse.

ValleyRAT has appeared in Silver Fox campaigns since at least 2023, typically aimed at financially exposed organizations across East Asia. What’s different here is the target profile — industrial manufacturing in Japan — and the use of drivers not previously attributed to this group. Per THN’s reporting, the campaign also includes newly observed abuse of a legitimate tool; the full technical breakdown is in the original writeup.

The IT/OT boundary question: A persistent backdoor in the IT layer of an industrial manufacturer is not automatically contained to the IT layer. ValleyRAT is built for durable access, not quick cash. The critical question — how far into the operational environment the access extended — isn’t answered in the current public reporting.

This is Silver Fox’s second publicly documented capability expansion in roughly three weeks. The group’s MODBEACON Rust RAT with gRPC-based C2 showed investment in custom malware. This BYOVD campaign shows investment in the initial access and persistence mechanics to deliver it — two separate capability tracks, not a single tool getting a refresh.

Earlier this week we noted Cruciferra bundling BYOVD as a commodity feature available to multiple threat clusters. Silver Fox’s version isn’t commodity — it’s a group-built chain using new drivers. The technique is the same. The investment level is different.

What to do if you’re in scope:

  • Enable Microsoft’s Vulnerable Driver Blocklist and HVCI where your hardware and workloads support it — this raises the bar for BYOVD attacks without eliminating them.
  • Review EDR telemetry for unusual kernel driver loads outside normal patch windows.
  • Any detection of ValleyRAT (Winos 4.0) components warrants full incident scope; this tool is designed for persistence, not fast monetization.
  • If you’re in industrial manufacturing with Japanese or regional East Asian exposure, treat this as targeted, not opportunistic.

The BYOVD driver-blocklist cycle has been a known dynamic long enough that “use three drivers” is the obvious adaptation to single-driver detection. That it took this long to show up in a publicly reported Silver Fox campaign is the more interesting data point.

Found this useful? Share it.