The Chinese cybercrime group Silver Fox targeted a Japanese manufacturer this month using a complex three-driver BYOVD chain and ValleyRAT malware [1].
This breach highlights the increasing sophistication of state-linked actors targeting the industrial manufacturing sector. By bypassing security kernels, these attackers can maintain long-term access to sensitive corporate infrastructure without detection.
The group utilized a "Bring Your Own Vulnerable Driver" (BYOVD) technique to compromise the organization [1]. This method involves installing a legitimate but vulnerable driver to gain kernel-level privileges, effectively disabling security software. In this specific operation, the group employed a chain of three different drivers to achieve the breach [1].
Once the security defenses were neutralized, Silver Fox deployed ValleyRAT, also known as Winos 4.0 [1]. This remote access trojan allows attackers to monitor user activity, steal files, and execute commands remotely. The primary objective of the campaign was to establish persistent remote access to the manufacturer's network [1].
Researchers noted the evolving nature of the group's tactics. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate," the report from The Hacker News said [1].
The attack specifically targeted an organization within the industrial manufacturing sector in Japan [1]. The use of ValleyRAT suggests a goal of long-term espionage or data exfiltration rather than immediate financial disruption. By leveraging legitimate drivers, the attackers minimized the risk of triggering traditional antivirus alerts, a hallmark of advanced persistent threat activity.
“The Chinese cybercrime group Silver Fox targeted a Japanese manufacturer this month.”
The use of a three-driver BYOVD chain indicates a high level of technical maturity, as it allows attackers to circumvent modern operating system protections. For industrial manufacturers, this means that standard endpoint detection and response tools may be insufficient if they cannot detect the loading of legitimate but vulnerable third-party drivers. This trend suggests a shift toward 'living-off-the-land' techniques where legitimate software is weaponized to avoid detection.



