Silver Fox Hackers Chain Three Vulnerable Drivers to Plant ValleyRAT on Japanese Factory
The Chinese crew abused legitimate but flawed Windows drivers to switch off security tools before dropping a remote-access trojan.

Key points
- Silver Fox, a Chinese cybercrime group, hit a Japanese industrial manufacturer using three vulnerable Windows drivers to disable security software.
- The attackers finished the job by installing ValleyRAT, also known as Winos 4.0, a tool that gives them long-term remote control of the machine.
- Two of the drivers had not been seen abused in this way before, expanding the pool of "trusted" software that criminals can turn against defenders.
- The technique is called BYOVD, short for Bring Your Own Vulnerable Driver, and it works because Windows still trusts signed drivers even when they are known to be broken.
A Chinese hacking crew called Silver Fox has been caught breaking into a Japanese factory by smuggling in old, flawed Windows drivers and using them to switch off the company's security tools.
Once the alarms were silenced, the attackers installed ValleyRAT, a remote-access trojan, meaning a program that lets criminals control the computer from the other side of the world as if they were sitting at the keyboard. It is also known as Winos 4.0.
The campaign was first reported by The Hacker News, based on research into a single victim in Japan's industrial manufacturing sector.
What is a "vulnerable driver" attack?
It is a trick where hackers bring their own broken software onto a machine to get powers Windows would normally deny them. A driver is a small program that lets Windows talk to hardware like a printer or a graphics card. Drivers run deep inside the system with very high privileges.
Windows only trusts drivers that have been digitally signed by a recognised vendor. That signature is meant to be a stamp of approval.
The problem: plenty of old signed drivers have known bugs in them. If an attacker can drop one of those onto a computer, Windows still trusts it, and the attacker can use the bug to reach into the guts of the operating system.
Security people call this Bring Your Own Vulnerable Driver, or BYOVD. Think of it like a burglar showing up with a legitimate uniform from a defunct security firm. The badge is real. The uniform is real. The person wearing it should not be there.
How did Silver Fox pull it off?
The group chained together three vulnerable drivers, two of which researchers say had not been seen abused in the wild before this campaign. Once loaded, the drivers were used to kill or blind the antivirus and endpoint protection software running on the target machine.
With the defences down, Silver Fox planted ValleyRAT for persistent access. Persistent access means the malware survives reboots and quietly phones home, giving the attackers a permanent back door into the factory's network.
| Detail | What we know |
|---|---|
| Attacker | Silver Fox (China-linked cybercrime group) |
| Victim | A Japanese industrial manufacturing firm |
| Technique | BYOVD chain using three vulnerable drivers |
| Final payload | ValleyRAT, also called Winos 4.0 |
Should ordinary people be worried?
Not directly. This attack targeted a specific company's computers, not consumer laptops or phones, and it required the attackers to already have a foothold on the network to drop the drivers in the first place.
The wider worry is for anyone whose data sits inside industrial firms. If Silver Fox is inside a manufacturer's network for weeks or months, they can steal designs, customer lists, and payment details. Staff at affected companies should be alert to unusual login prompts and phishing emails, where criminals send fake messages to trick people into handing over passwords.
Why this matters for defenders
BYOVD keeps working because Microsoft's driver blocklist, the official list of known-bad drivers Windows should refuse to load, is not updated fast enough and is not switched on by default on every system. Every new vulnerable driver Silver Fox adds to its toolkit is one more skeleton key that will keep working until Microsoft and antivirus vendors catch up.
ValleyRAT itself is not new. It has been tied to Silver Fox operations against Chinese-speaking targets for over a year. Seeing it aimed at a Japanese manufacturer suggests the group is broadening its geographic appetite.



