Threat Advisory

Silver Fox APT Exploits Kernel Mode Drivers

Threat: Malware Campaign
Threat Actor Name: Silver Fox APT
Threat Actor Type: APT
Targeted Region: China
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Silver Fox APT group is behind the attack, which involves the abuse of a previously unknown vulnerable driver to terminate protected processes and facilitate the delivery of the ValleyRAT backdoor. The attackers target various sectors, particularly those in Asia, with the goal of gaining remote access and control capabilities. The campaign's significance lies in its ability to bypass traditional detection mechanisms and evade trust-based defenses.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The Silver Fox APT group is behind the attack, which involves the abuse of a previously unknown vulnerable driver to terminate protected processes and facilitate the delivery of the ValleyRAT backdoor. The attackers target various sectors, particularly those in Asia, with the goal of gaining remote access and control capabilities. The campaign's significance lies in its ability to bypass traditional detection mechanisms and evade trust-based defenses.[emaillocker id="1283"]

The malware infects systems through a custom loader designed to abuse kernel drivers, specifically the WatchDog Antimalware driver, to terminate security-related processes. Once inside, the malware delivers a multi-stage payload, ultimately installing the ValleyRAT backdoor, which provides remote access and control capabilities. The attackers maintain control by using a modified version of the patched driver, which preserves the driver's valid Microsoft signature while generating a new file hash, effectively bypassing hash-based blocklists.

This threat is significant for organisations due to its ability to evade detection and bypass traditional defenses. The use of signed-but-vulnerable drivers makes it difficult to detect and recover from the attack. To defend against this threat, organisations should prioritise patching and monitoring, ensuring that all systems are up-to-date, and implementing robust endpoint protection measures to prevent the exploitation of vulnerable drivers. Additionally, organisations should be vigilant in monitoring for suspicious activity and have incident response plans in place to quickly respond to potential attacks.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Persistence T1543.004 Create or Modify System Process Launch Daemon
Persistence T1543.003 Create or Modify System Process Windows Service
Privilege Escalation T1068 Exploitation for Privilege Escalation
Defense Evasion T1574.001 Hijack Execution Flow DLL Search Order Hijacking
Defense Evasion T1562.001 Impair Defenses Disable or Modify Tools
Defense Evasion T1497.001 Virtualization/Sandbox Evasion System Checks
Defense Evasion T1027.002 Obfuscated Files or Information Software Packing
Command and Control T1105 Ingress Tool Transfer

REFERENCES:

reports contain further technical details:
https://research.checkpoint.com/2025/silver-fox-apt-vulnerable-drivers/
https://securityonline.info/silverfox-valleyrat-byovd-campaign/

[/emaillocker]
crossmenu