# SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD

> SilverFox (aka Void Arachne / SwimSnake) is targeting a Japanese industrial manufacturer with invoice-themed phishing delivered via abused QQ and Tencent Cloud infrastructure, DLL side-loading through trojanized Zeon Corporation Right PDF utilities, and a three-driver Bring-Your-Own-Vulnerable-Driver (BYOVD) framework (wsftprm.sys/CVE-2023-52271, BootRepair.sys, EnPortv.sys) to kill security products at kernel level, unhook NTDLL, and deploy ValleyRAT (Winos 4.0) with a dual-layer watchdog recovery architecture.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-08-06T19:15:54.077Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1787
- **ID:** TL-2026-1787
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Void Arachne (China)
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2023-52271

## Description

Cato Networks CTRL documented an evolved SilverFox intrusion chain against a Japanese industrial manufacturing organization beginning with an invoice-themed phishing email whose attacker-controlled content is hosted on legitimate QQ (file.wx2.qq.com) and Tencent Cloud COS (hrefbfdhfhgre-1422102728.cos.ap-hongkong.myqcloud.com) infrastructure, evading reputation-based network defenses. The email leads to a timestamped ZIP archive (e.g. 20260608154418.zip) that triggers DLL side-loading: the legitimate, digitally signed Zeon Corporation Right PDF utilities ConvertToPDF.exe and PDFDirect.exe resolve a malicious PDFCORE8.dll from their local working directory (previously undocumented abuse of these binaries for side-loading), sometimes staged under the decoy filename MicrosoftEdgeUpdate.exe.

PDFCORE8.dll embeds three RC4-encrypted (hardcoded 128-bit key BB7BBB62FD9C76D5DDF37F17DDC3E7FF) vulnerable kernel drivers as PE resources: wsftprm.sys (Topaz OFD's Topaz Warsaw antifraud driver, CVE-2023-52271, previously associated with SilverFox), and two previously undocumented SilverFox drivers, BootRepair.sys (a legitimate Lenovo PC Manager driver signed 2018-01-03) and EnPortv.sys. Each driver is decrypted, dropped, loaded as a kernel service via the standard Service Control Manager workflow, and then abused through an IOCTL that reaches ZwTerminateProcess() in kernel context with no caller validation — killing Protected-Process-Light-protected EDR/AV agents that user-mode code cannot touch. The framework is modular, reusing the same loader logic while swapping driver image, device object name (\\.\EnPortv, \\.\Warsaw_PM, \\.\BootRepair), and IOCTL code (0x223078, 0x22201C, 0x222014 respectively) per embedded driver.

After clearing security tooling, the loader performs NTDLL unhooking by loading a clean copy of ntdll.dll from disk and overwriting the in-memory .text section to strip user-mode inline hooks, then injects into a suspended svchost.exe via classic thread-context hijacking (CreateProcessA + CREATE_SUSPENDED, VirtualAllocEx, WriteProcessMemory, GetThreadContext/SetThreadContext, ResumeThread). API and library names are resolved dynamically via runtime-constructed strings and LoadLibraryW/GetProcAddress to frustrate static detection. Final-stage shellcode and C2 configuration are stored not on disk but in the registry (HKCU\Console\0 for shellcode, HKLM\SOFTWARE\IpDates_sun for C2 config), patched into a "FaCai2024" placeholder marker (Mandarin for "become prosperous") — a marker and registry technique previously documented by Tencent Security in connection with the distinct-but-related FaCai phishing group, providing a moderate-confidence attribution link. The implant establishes a dual-layer recovery architecture: an internal monitor routine checks the injected svchost.exe's exit code each cycle and recreates the payload if it is not STILL_ACTIVE, while an external batch-script watchdog (embedded as PE resource 4020) polls every 30 seconds via tasklist.exe/find.exe/timeout.exe and relaunches the loader if killed; a scheduled task (via schtasks.exe) additionally relaunches the loader chain at logon. Final C2 is ValleyRAT (aka Winos 4.0, Gh0st RAT lineage) beaconing to 43.128.26.132 over non-standard ports 778/779. ValleyRAT's broader plugin architecture (documented across independent reporting on this malware family) provides system reconnaissance, keylogging, screen/audio capture, credential theft, remote command execution, file exfiltration, and a kernel-mode "Driver Plugin" rootkit capability, indicating this Japan intrusion likely carries the same post-compromise capability set once the RAT is live.

SilverFox (aka Void Arachne, SwimSnake, The Great Thief of Valley, UTG-Q-1000) is a China-based intrusion set active since at least 2022 that increasingly blurs cybercrime and espionage-style operations, with a multi-year history of ValleyRAT/Winos 4.0 campaigns against Taiwan, India, and now Japan. Cato CTRL attempted coordinated disclosure to Zeon/Right PDF (2026-07-01, Ticket 13493, DLL side-loading) and Tencent (2026-07-12, Ticket 69528, QQ/Cloud infrastructure abuse); neither vendor had responded as of the 2026-07-20 disclosure deadline. Neither BootRepair.sys nor EnPortv.sys currently carry a CVE; wsftprm.sys (CVE-2023-52271, CVSS 3.1 6.5) is not on Microsoft's vulnerable-driver blocklist and loads on fully patched, Secure Boot + HVCI-enabled Windows 11.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1106 Native API
- T1129 Shared Modules
- T1543 Create or Modify System Process
- T1053 Scheduled Task/Job
- T1574 Hijack Execution Flow
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1055 Process Injection
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1685 Disable or Modify Tools
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1112 Modify Registry
- T1070 Indicator Removal
- T1056 Input Capture
- T1057 Process Discovery
- T1082 System Information Discovery
- T1056 Input Capture
- T1113 Screen Capture
- T1123 Audio Capture
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [SilverFox targets Japanese manufacturer with advanced ValleyRAT campaign](https://securityaffairs.com/196347/apt/silverfox-targets-japanese-manufacturer-with-advanced-valleyrat-campaign.html)
- [Cato CTRL Threat Research: SilverFox Evolves — Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan](https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/)
- [SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT](https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html)
- [Silver Fox group uses new drivers in BYOVD attacks against Japanese manufacturer](https://www.scworld.com/brief/silver-fox-group-uses-new-drivers-in-byovd-attacks-against-japanese-manufacturer)
- [Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign](https://gbhackers.com/silver-fox-apt/)
- [Silver Fox APT Exploits DLL Sideloading and BYOVD In Stealth Campaign](https://cyberpress.org/silver-fox-abuses-drivers/)
- [GHSA-r67f-8hjg-55w3: wsftprm.sys kernel driver vulnerable to arbitrary process termination](https://github.com/advisories/GHSA-r67f-8hjg-55w3)
- [CVE-2023-52271 Detail](https://nvd.nist.gov/vuln/detail/CVE-2023-52271)
- [Vulnerability Notice: Topaz Antifraud (wsftprm.sys)](https://northwave-cybersecurity.com/vulnerability-notice-topaz-antifraud)
- [BYOVD-CVE-2023-52271-POC](https://github.com/victoni/BYOVD-CVE-2023-52271-POC)
- [LOLDrivers: BootRepair.sys driver entry](https://www.loldrivers.io/drivers/7cc0a40d-7902-4400-9fc4-0070053991cb/)
- [LOLDrivers Sigma detection: Vulnerable Driver Load By Name](https://github.com/magicsword-io/LOLDrivers/blob/main/detections/sigma/driver_load_win_vuln_drivers_names.yml)
- [Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware](https://thehackernews.com/2025/12/silver-fox-targets-indian-users-with.html)
- [Silver Fox APT Uses Winos 4.0 Malware in Cyber Attacks Against Taiwanese Organizations](https://thehackernews.com/2025/02/silver-fox-apt-uses-winos-40-malware-in.html)
- [APT Profile - Silver Fox](https://www.cyfirma.com/research/apt-profile-silver-fox/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1787
