The record
Written from the 1 report below. Nothing here is unsourced.
- A Chinese cybercrime group called Silver Fox targeted a Japanese industrial manufacturing company using malware known as ValleyRAT, which gives attackers remote control of infected computers.
- The attack began with a fake invoice phishing email and used a technique called BYOVD (bring your own vulnerable driver) to gain deep system access and disable security tools on the victim's machine.
- Researchers highlighted that the group used two drivers not previously seen in its attacks, arranged in a modular, plug-and-play framework designed to keep the malware running even if parts of it are removed.
- The malware includes layered recovery mechanisms, meaning defenders must eliminate multiple components simultaneously to fully remove the infection.
What to watch next
- Whether Silver Fox expands use of the newly observed drivers (BootRepair.sys and EnPortv.sys) in future campaigns against other sectors or regions.
- Whether Japanese industrial firms increase security measures in response to invoice-themed phishing and BYOVD threats.
- Whether researchers confirm a definitive link between Silver Fox and newly tracked tools such as Atlas RAT, which so far rests on circumstantial evidence.
Coverage1
1 report
English national1
All filed from India
Named China · Japan · South Korea · Japanese manufacturer · Zeon Corporation · BootRepair.sys · Cato Networks · EnPortv.sys · Guy Waizel · Idan Tarab · QQ · Shani Kurtzberg · Silver Fox · Tencent Cloud · Tomer Pugach
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
