As cited
Copy frozen at (site build).
threat intel
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
Chinese cybercrime group Silver Fox executed a targeted attack against a Japanese industrial manufacturer using a bring your own vulnerable driver (BYOVD) chain to load ValleyRAT malware for persistent remote access. The campaign involved newly identified vulnerable drivers and abuse of legitimate tools to establish and maintain system compromise.
Why it matters: Industrial manufacturers relying on Windows systems are at immediate risk from sophisticated Chinese threat actors using BYOVD techniques that bypass driver-signing requirements; organizations should audit running drivers and monitor for suspicious unsigned or signed-but-malicious drivers.
- Source published
- First seen by Cybersecurity Tracker