Find notable cyber news and cases, enriched with sources, timelines, and signals.

Silver Fox BYOVD phishing and DLL sideloading campaign against Japanese manufacturing target

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

The Silver Fox campaign is using BYOVD, DLL sideloading, and invoice-themed phishing to deploy ValleyRAT (Winos 4.0) for persistent remote access. The activity targeted a Japanese industrial manufacturing organization and used legitimate QQ and Tencent Cloud hosting to move the attack chain forward. The operators also added new drivers and dual watchdog recovery to make the intrusion harder to stop.

Related Happenings

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

Silver Fox South Asia phishing campaign

Campaign
H score34 First: 24.03.2026 18:00 Last: 24.03.2026 18:00 Sources 1

About this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...

Silver Fox Microsoft Teams SEO poisoning campaign

Campaign
H score32 First: 04.12.2025 19:25 Last: 04.12.2025 19:25 Sources 1

About this happening: The Silver Fox operation is using SEO poisoning and Microsoft Teams lures to deliver ValleyRAT to Chinese-speaking users in China, making the campaign an activ...

Timeline

  1. 30.07.2026 13:32 1 articles · 2h ago

    Silver Fox deploys ValleyRAT through BYOVD and DLL sideloading against a Japanese manufacturer

    Initial Disclosure

    Silver Fox used an invoice-themed phishing lure, attacker-controlled content hosted on QQ and Tencent Cloud, and a ZIP-based DLL sideloading chain to target a Japanese industrial manufacturing organization and deploy ValleyRAT (aka Winos 4.0) for persistent remote access. The operators broadened the intrusion with BootRepair.sys, EnPortv.sys, and wsftprm.sys in a modular three-driver BYOVD framework, alongside NTDLL unhooking, process injection, registry-based payload storage, and dual watchdog recovery to evade security controls and keep the implant running.

    Show sources