Threat reportMalwareTL-2026-1787
SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD
SilverFox APT Deploys Advanced ValleyRAT Campaign Against (TL-2026-1787), also tracked as Winos 4.0 Campaign, is a high-severity malware campaign, first published 2026-07-31 and last reviewed 2026-08-06. It is attributed to Void Arachne (China) with high confidence, affects Zeon Corporation Right PDF Suite (ConvertToPDF.exe, PDFDirect.exe), references 1 CVE (CVE-2023-52271), maps to 26 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 26MITRE ATT&CK
- Actors
- 1Void Arachne
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1787
- Threat ID
- TL-2026-1787
- Also known as
- Winos 4.0 Campaign, SilverFox Evolves
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Void Arachne
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- manufacturing, industrial, government administration, finance, technology, health
- Target regions
- japan, taiwan, india, malaysia, Southeast Asia, East Asia, South Asia
- Detection rules
- 9
- Indicators of compromise
- 34
- Updates
- 2026-08-06 · revalidated 1× · latest source
Malware and tooling in SilverFox APT Deploys Advanced ValleyRAT Campaign Against
Malware and tooling: ValleyRAT, PDFCORE8.dll BYOVD loader framework
How SilverFox APT Deploys Advanced ValleyRAT Campaign Against works
SilverFox (aka Void Arachne / SwimSnake) is targeting a Japanese industrial manufacturer with invoice-themed phishing delivered via abused QQ and Tencent Cloud infrastructure, DLL side-loading through trojanized Zeon Corporation Right PDF utilities, and a three-driver Bring-Your-Own-Vulnerable-Driver (BYOVD) framework (wsftprm.sys/CVE-2023-52271, BootRepair.sys, EnPortv.sys) to kill security products at kernel level, unhook NTDLL, and deploy ValleyRAT (Winos 4.0) with a dual-layer watchdog recovery architecture.
Cato Networks CTRL documented an evolved SilverFox intrusion chain against a Japanese industrial manufacturing organization beginning with an invoice-themed phishing email whose attacker-controlled content is hosted on legitimate QQ (file.wx2.qq.com) and Tencent Cloud COS (hrefbfdhfhgre-1422102728.cos.ap-hongkong.myqcloud.com) infrastructure, evading reputation-based network defenses. The email leads to a timestamped ZIP archive (e.g. 20260608154418.zip) that triggers DLL side-loading: the legitimate, digitally signed Zeon Corporation Right PDF utilities ConvertToPDF.exe and PDFDirect.exe resolve a malicious PDFCORE8.dll from their local working directory (previously undocumented abuse of these binaries for side-loading), sometimes staged under the decoy filename MicrosoftEdgeUpdate.exe.
PDFCORE8.dll embeds three RC4-encrypted (hardcoded 128-bit key BB7BBB62FD9C76D5DDF37F17DDC3E7FF) vulnerable kernel drivers as PE resources: wsftprm.sys (Topaz OFD's Topaz Warsaw antifraud driver, CVE-2023-52271, previously associated with SilverFox), and two previously undocumented SilverFox drivers, BootRepair.sys (a legitimate Lenovo PC Manager driver signed 2018-01-03) and EnPortv.sys. Each driver is decrypted, dropped, loaded as a kernel service via the standard Service Control Manager workflow, and then abused through an IOCTL that reaches ZwTerminateProcess() in kernel context with no caller validation — killing Protected-Process-Light-protected EDR/AV agents that user-mode code cannot touch. The framework is modular, reusing the same loader logic while swapping driver image, device object name (\\.\EnPortv, \\.\Warsaw_PM, \\.\BootRepair), and IOCTL code (0x223078, 0x22201C, 0x222014 respectively) per embedded driver.
After clearing security tooling, the loader performs NTDLL unhooking by loading a clean copy of ntdll.dll from disk and overwriting the in-memory .text section to strip user-mode inline hooks, then injects into a suspended svchost.exe via classic thread-context hijacking (CreateProcessA + CREATE_SUSPENDED, VirtualAllocEx, WriteProcessMemory, GetThreadContext/SetThreadContext, ResumeThread). API and library names are resolved dynamically via runtime-constructed strings and LoadLibraryW/GetProcAddress to frustrate static detection. Final-stage shellcode and C2 configuration are stored not on disk but in the registry (HKCU\Console\0 for shellcode, HKLM\SOFTWARE\IpDates_sun for C2 config), patched into a "FaCai2024" placeholder marker (Mandarin for "become prosperous") — a marker and registry technique previously documented by Tencent Security in connection with the distinct-but-related FaCai phishing group, providing a moderate-confidence attribution link. The implant establishes a dual-layer recovery architecture: an internal monitor routine checks the injected svchost.exe's exit code each cycle and recreates the payload if it is not STILL_ACTIVE, while an external batch-script watchdog (embedded as PE resource 4020) polls every 30 seconds via tasklist.exe/find.exe/timeout.exe and relaunches the loader if killed; a scheduled task (via schtasks.exe) additionally relaunches the loader chain at logon. Final C2 is ValleyRAT (aka Winos 4.0, Gh0st RAT lineage) beaconing to 43.128.26.132 over non-standard ports 778/779. ValleyRAT's broader plugin architecture (documented across independent reporting on this malware family) provides system reconnaissance, keylogging, screen/audio capture, credential theft, remote command execution, file exfiltration, and a kernel-mode "Driver Plugin" rootkit capability, indicating this Japan intrusion likely carries the same post-compromise capability set once the RAT is live.
SilverFox (aka Void Arachne, SwimSnake, The Great Thief of Valley, UTG-Q-1000) is a China-based intrusion set active since at least 2022 that increasingly blurs cybercrime and espionage-style operations, with a multi-year history of ValleyRAT/Winos 4.0 campaigns against Taiwan, India, and now Japan. Cato CTRL attempted coordinated disclosure to Zeon/Right PDF (2026-07-01, Ticket 13493, DLL side-loading) and Tencent (2026-07-12, Ticket 69528, QQ/Cloud infrastructure abuse); neither vendor had responded as of the 2026-07-20 disclosure deadline. Neither BootRepair.sys nor EnPortv.sys currently carry a CVE; wsftprm.sys (CVE-2023-52271, CVSS 3.1 6.5) is not on Microsoft's vulnerable-driver blocklist and loads on fully patched, Secure Boot + HVCI-enabled Windows 11.
MITRE ATT&CK techniques used in TL-2026-1787
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process
Privilege Escalation
T1055 Process Injection; T1068 Exploitation for Privilege Escalation; T1543 Create or Modify System Process
Credential Access
Collection
T1056 Input Capture; T1113 Screen Capture; T1123 Audio Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
Execution
T1106 Native API; T1129 Shared Modules; T1204 User Execution
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Initial Access
stealth
Resource Development
Affected products and versions in SilverFox APT Deploys Advanced ValleyRAT Campaign Against
- Zeon Corporation — Right PDF Suite (ConvertToPDF.exe, PDFDirect.exe)
Vulnerable versions: all shipping versions vulnerable to local-directory DLL side-loading of PDFCORE8.dll as of 2026-07-31
Fixed in: none disclosed; vendor unresponsive to 2026-07-01 disclosure (Ticket 13493) - Topaz OFD — Topaz Warsaw Antifraud driver (wsftprm.sys / wsddprm)
Vulnerable versions: 2.0.0.0 (CVE-2023-52271)
Fixed in: none disclosed; driver not on Microsoft's vulnerable driver blocklist as of 2026-07-31 - Lenovo — Lenovo PC Manager (BootRepair.sys)
Vulnerable versions: build compiled 2018-01-03, signed via Symantec Class 3 SHA256 Code Signing CA
Fixed in: none disclosed - Unknown — EnPortv.sys (parent product not publicly identified)
Vulnerable versions: sample embedded as PDFCORE8.dll PE resource 4024
Fixed in: none disclosed - Tencent — QQ file service (wx2.qq.com) / Tencent Cloud Object Storage (COS)
Vulnerable versions: legitimate service abused for payload hosting/delivery; not a software vulnerability
Fixed in: none; vendor unresponsive to 2026-07-12 abuse report (Ticket 69528)
Remediation for SilverFox APT Deploys Advanced ValleyRAT Campaign Against
Patches
- No vendor patch exists for CVE-2023-52271 (wsftprm.sys / Topaz Warsaw); mitigate via driver blocklisting since the driver is not on Microsoft's default blocklist
- Zeon Corporation (Right PDF) has issued no fix or guidance for the ConvertToPDF.exe/PDFDirect.exe DLL side-loading weakness; disclosed 2026-07-01 (Ticket 13493), no vendor response as of 2026-07-20
- Tencent has issued no remediation for QQ/Tencent Cloud infrastructure abuse used in payload delivery; disclosed 2026-07-12 (Ticket 69528), no vendor response as of 2026-07-20
Immediate actions
- Block network egress to C2 43.128.26.132 (TCP ports 778/779) at perimeter firewall, proxy, and DNS layers
- Deploy or verify Microsoft's vulnerable driver blocklist / HVCI covers wsftprm.sys, BootRepair.sys, and EnPortv.sys; add hash-based blocks where those mechanisms cannot be enabled
- Alert on kernel service creation referencing device objects \\.\EnPortv, \\.\Warsaw_PM, or \\.\BootRepair, or IOCTL codes 0x223078 / 0x22201C / 0x222014
- Hunt for ConvertToPDF.exe or PDFDirect.exe executing from %TEMP% or other user-writable directories rather than the standard Right PDF install path
- Hunt for processes named or renamed MicrosoftEdgeUpdate.exe that are not signed by Microsoft or not running from the genuine Edge update path
- Hunt for REG_BINARY writes to HKCU\Console\0 and HKLM\SOFTWARE\IpDates_sun
Workarounds
- Add wsftprm.sys, BootRepair.sys, and EnPortv.sys to a local driver deny-list where WDAC/HVCI cannot be deployed fleet-wide
- Isolate, remove, or code-sign-restrict standalone copies of ConvertToPDF.exe/PDFDirect.exe found outside a controlled, write-protected installation directory
- Monitor and alert on binary-blob writes under HKCU\Console and HKLM\SOFTWARE via EDR registry-write telemetry
Longer-term hardening
- Enforce Windows HVCI and the Microsoft vulnerable driver blocklist fleet-wide to prevent arbitrary BYOVD driver loading
- Deploy EDR/AV tamper-resistance (PPL, ELAM, anti-BYOVD kernel monitoring) capable of surviving ZwTerminateProcess-based kill attempts
- Implement WDAC / application allow-listing to prevent unexpected DLLs (e.g. PDFCORE8.dll) from loading alongside trusted, signed applications
- Restrict or proxy-inspect outbound access to QQ (qq.com) and unmanaged Tencent Cloud COS buckets from corporate endpoints where not business-justified
- Build threat-hunting playbooks for thread-context hijacking into suspended svchost.exe and for registry-resident shellcode/config storage
CVEs associated with SilverFox APT Deploys Advanced ValleyRAT Campaign Against
Weaknesses (CWE) in SilverFox APT Deploys Advanced ValleyRAT Campaign Against
Timeline of SilverFox APT Deploys Advanced ValleyRAT Campaign Against
- CVE-2023-52271 (wsftprm.sys / Topaz Warsaw antifraud driver arbitrary PPL process termination via IOCTL 0x22201C) is publicly disclosed by Northwave Cyber Security; later weaponized by SilverFox for BYOVD attacks.
- Silver Fox APT observed using Winos 4.0 malware in campaigns against Taiwanese organizations, establishing the group's Winos/ValleyRAT lineage.
- Silver Fox targets Indian users with tax-themed phishing emails delivering ValleyRAT malware, showing continued regional expansion of the same malware family.
- Huntress publishes analysis of EnPortv.sys BYOVD abuse (identified as a Guidance Software/EnCase forensic driver, IOCTL 0x223078) in a SonicWall SSLVPN intrusion; the same driver was later matched to this SilverFox campaign's EnPortv.sys sample.
- Silver Fox expands its Asia campaign with AtlasCross RAT and fake domains, continuing the multi-region targeting pattern later observed in the Japan intrusion.
- Earliest observed evidence of this SilverFox campaign: timestamp-based phishing archive 20260608154418.zip used in initial delivery.
- Cato CTRL attempts coordinated disclosure to Zeon/Right PDF regarding the ConvertToPDF.exe/PDFDirect.exe DLL side-loading weakness (Ticket 13493); no vendor response received.
- Cato CTRL attempts coordinated disclosure to Tencent regarding abuse of QQ file-delivery and Tencent Cloud COS infrastructure (Ticket 69528); no vendor response received.
- Coordinated disclosure window closes with no response from either Zeon/Right PDF or Tencent.
- Cato Networks CTRL publishes the full technical dissection of the SilverFox ValleyRAT campaign ("SilverFox Evolves"), detailing the three-driver BYOVD framework, DLL side-loading, and dual-watchdog recovery architecture.
- The Hacker News, SC Media, GBHackers, and Cyberpress publish independent coverage of the Cato CTRL findings on the SilverFox BYOVD/ValleyRAT campaign.
- SecurityAffairs reports on the campaign, driving broader industry awareness and prompting this hunt/research cycle.
- Cyber Security News publishes additional coverage of the campaign; Cato CTRL reports its own NGAM product blocked PDFCORE8.dll in this intrusion before ValleyRAT could establish C2 (does not indicate the broader campaign is contained).
Update history for TL-2026-1787
- 2026-08-06 — SilverFox Hijacks Trusted PDF Software in DLL Sideloading Campaign Deploying ValleyRAT Against Japanese Manufacturer: What changed Attribution confidence escalated MEDIUM - HIGH, supported by new corroborating evidence: EnPortv.sys was previously an unidentified driver ("parent product not publicly identified") and is now attributed to Guidance Software/En
Sources cited for SilverFox APT Deploys Advanced ValleyRAT Campaign Against
- SilverFox targets Japanese manufacturer with advanced ValleyRAT campaign
- Cato CTRL Threat Research: SilverFox Evolves — Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
- Silver Fox group uses new drivers in BYOVD attacks against Japanese manufacturer
- Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign
- Silver Fox APT Exploits DLL Sideloading and BYOVD In Stealth Campaign
- GHSA-r67f-8hjg-55w3: wsftprm.sys kernel driver vulnerable to arbitrary process termination
- CVE-2023-52271 Detail
- Vulnerability Notice: Topaz Antifraud (wsftprm.sys)
- BYOVD-CVE-2023-52271-POC
- LOLDrivers: BootRepair.sys driver entry
- LOLDrivers Sigma detection: Vulnerable Driver Load By Name
- Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware
- Silver Fox APT Uses Winos 4.0 Malware in Cyber Attacks Against Taiwanese Organizations
- APT Profile - Silver Fox
Detection coverage for TL-2026-1787
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1787 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1787
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.