started · updated
Silver Fox targets Japanese industrial maker with ValleyRAT malware
Chinese cyber‑espionage group Silver Fox carried out a campaign against a Japanese industrial manufacturer, deploying the remote‑access trojan ValleyRAT. The attackers began with a phishing email disguised as an invoice, hosting malicious content on legitimate QQ and Tencent Cloud services. They used signed Zeon Corporation utilities (ConvertToPDF.exe and PDFDirect.exe) to sideload a malicious PDFCORE8.dll, which embeds three vulnerable kernel drivers—BootRepair.sys, EnPortv.sys and wsftprm.sys—in a bring‑your‑own‑vulnerable‑driver (BYOVD) chain. The driver framework grants kernel‑level execution, terminates security tools, replaces NTDLL sections, and contacts a C2 server (IP 43.128.26[. ]132) to download shellcode that is injected into a suspended svchost.exe process. Researchers at Cato Networks documented the novel three‑driver persistence architecture and highlighted its resilience against defensive removal.
The campaign demonstrates an evolving tactic in cyber‑espionage, combining social engineering, legitimate cloud infrastructure, DLL sideloading, and multi‑driver kernel abuse to maintain long‑term access to high‑value industrial targets.
Entities
Cato Networks · Japanese industrial manufacturer · Silver Fox · ValleyRAT · Zeon Corporation