Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, silverfox, byovd, valleyrat, japan, manufacturing, cybercrime] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Summary

The Chinese cybercrime group Silver Fox (SilverFox) has been observed using new bring-your-own-vulnerable-driver (BYOVD) techniques targeting a Japanese industrial manufacturing organisation. The attack chain begins with an invoice-themed phishing lure, uses DLL sideloading via QQ and Tencent Cloud services, deploys three drivers for kernel access, and ultimately delivers ValleyRAT (Winos 4.0) for persistent remote access.

Key Details

  • Date: 2026-07-30
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Threat Actor: Silver Fox (SilverFox) โ€” Chinese cybercrime group
  • Target: Japanese industrial manufacturing organisation
  • Initial Access: Invoice-themed phishing lure
  • Technique: DLL sideloading via QQ and Tencent Cloud services
  • Exploitation: 3-driver bring-your-own-vulnerable-driver (BYOVD) chain for kernel access
  • Payload: ValleyRAT (Winos 4.0) โ€” persistent remote access

Source

See Also

  • Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors
  • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
  • Cyber Extortionists Steal Data from UK Department for Education