type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, silverfox, byovd, valleyrat, japan, manufacturing, cybercrime] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
Summary
The Chinese cybercrime group Silver Fox (SilverFox) has been observed using new bring-your-own-vulnerable-driver (BYOVD) techniques targeting a Japanese industrial manufacturing organisation. The attack chain begins with an invoice-themed phishing lure, uses DLL sideloading via QQ and Tencent Cloud services, deploys three drivers for kernel access, and ultimately delivers ValleyRAT (Winos 4.0) for persistent remote access.
Key Details
- Date: 2026-07-30
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- Threat Actor: Silver Fox (SilverFox) โ Chinese cybercrime group
- Target: Japanese industrial manufacturing organisation
- Initial Access: Invoice-themed phishing lure
- Technique: DLL sideloading via QQ and Tencent Cloud services
- Exploitation: 3-driver bring-your-own-vulnerable-driver (BYOVD) chain for kernel access
- Payload: ValleyRAT (Winos 4.0) โ persistent remote access
Source
See Also
- Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
- Cyber Extortionists Steal Data from UK Department for Education