EXECUTIVE SUMMARY
The Silver Fox APT group is behind the attack, which involves the abuse of a previously unknown vulnerable driver to terminate protected processes and facilitate the delivery of the ValleyRAT backdoor. The attackers target various sectors, particularly those in Asia, with the goal of gaining remote access and control capabilities. The campaign's significance lies in its ability to bypass traditional detection mechanisms and evade trust-based defenses.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The Silver Fox APT group is behind the attack, which involves the abuse of a previously unknown vulnerable driver to terminate protected processes and facilitate the delivery of the ValleyRAT backdoor. The attackers target various sectors, particularly those in Asia, with the goal of gaining remote access and control capabilities. The campaign's significance lies in its ability to bypass traditional detection mechanisms and evade trust-based defenses.[emaillocker id="1283"]
The malware infects systems through a custom loader designed to abuse kernel drivers, specifically the WatchDog Antimalware driver, to terminate security-related processes. Once inside, the malware delivers a multi-stage payload, ultimately installing the ValleyRAT backdoor, which provides remote access and control capabilities. The attackers maintain control by using a modified version of the patched driver, which preserves the driver's valid Microsoft signature while generating a new file hash, effectively bypassing hash-based blocklists.
This threat is significant for organisations due to its ability to evade detection and bypass traditional defenses. The use of signed-but-vulnerable drivers makes it difficult to detect and recover from the attack. To defend against this threat, organisations should prioritise patching and monitoring, ensuring that all systems are up-to-date, and implementing robust endpoint protection measures to prevent the exploitation of vulnerable drivers. Additionally, organisations should be vigilant in monitoring for suspicious activity and have incident response plans in place to quickly respond to potential attacks.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Persistence | T1543.004 | Create or Modify System Process | Launch Daemon |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | — |
| Defense Evasion | T1574.001 | Hijack Execution Flow | DLL Search Order Hijacking |
| Defense Evasion | T1562.001 | Impair Defenses | Disable or Modify Tools |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion | System Checks |
| Defense Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Command and Control | T1105 | Ingress Tool Transfer | — |
REFERENCES:
reports contain further technical details:
https://research.checkpoint.com/2025/silver-fox-apt-vulnerable-drivers/
https://securityonline.info/silverfox-valleyrat-byovd-campaign/