Tag: ValleyRAT

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
News

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

In order to provide ValleyRAT (also known as Winos 4.0) for permanent remote access, the Chinese cybercrime gang Silver Fox has been seen using new drivers as part of bring your own vulnerable driver (BYOVD) attacks against a Japanese company in the industrial manufacturing sector. According to an analysis by Cato Networks researchers Shani Kurtzberg, Tomer Pugach, Dr. Guy Waizel, Zohar Buber, Idan Tarab, and Shani Kurtzberg, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT operating. Before deploying ValleyRAT, the attack chain starts with an invoice-themed phishing lure that uses attacker-controlled content hosted on genuine QQ and Tencent Cloud se...