Silver Fox BYOVD phishing and DLL sideloading campaign against Japanese manufacturing target
Campaign
Summary
Hide ▲
Show ▼
The Silver Fox campaign is using BYOVD, DLL sideloading, and invoice-themed phishing to deploy ValleyRAT (Winos 4.0) for persistent remote access. The activity targeted a Japanese industrial manufacturing organization and used legitimate QQ and Tencent Cloud hosting to move the attack chain forward. The operators also added new drivers and dual watchdog recovery to make the intrusion harder to stop.
Related Happenings
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Silver Fox South Asia phishing campaign
Campaign
H score34
First: 24.03.2026 18:00
Last: 24.03.2026 18:00
Sources 1
About this happening:
The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Fox South Asia phishing campaign
CampaignAbout this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Fox Microsoft Teams SEO poisoning campaign
Campaign
H score32
First: 04.12.2025 19:25
Last: 04.12.2025 19:25
Sources 1
About this happening:
The Silver Fox operation is using SEO poisoning and Microsoft Teams lures to deliver ValleyRAT to Chinese-speaking users in China, making the campaign an activ...
Silver Fox Microsoft Teams SEO poisoning campaign
CampaignAbout this happening: The Silver Fox operation is using SEO poisoning and Microsoft Teams lures to deliver ValleyRAT to Chinese-speaking users in China, making the campaign an activ...
Timeline
-
30.07.2026 13:32 1 articles · 2h ago
Silver Fox deploys ValleyRAT through BYOVD and DLL sideloading against a Japanese manufacturer
Initial DisclosureSilver Fox used an invoice-themed phishing lure, attacker-controlled content hosted on QQ and Tencent Cloud, and a ZIP-based DLL sideloading chain to target a Japanese industrial manufacturing organization and deploy ValleyRAT (aka Winos 4.0) for persistent remote access. The operators broadened the intrusion with BootRepair.sys, EnPortv.sys, and wsftprm.sys in a modular three-driver BYOVD framework, alongside NTDLL unhooking, process injection, registry-based payload storage, and dual watchdog recovery to evade security controls and keep the implant running.
Show sources
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT — thehackernews.com — 30.07.2026 13:32