Silver Fox Hackers Chain Three Vulnerable Drivers to Plant ValleyRAT on Japanese Factory

The Chinese crew abused legitimate but flawed Windows drivers to switch off security tools before dropping a remote-access trojan.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Photoreal editorial news image, 16:9, full frame edge to edge, dim server room inside a Taiwanese electronics manufacturing facility, blue and amber status ligh
Share

Key points

  • Silver Fox, a Chinese cybercrime group, hit a Japanese industrial manufacturer using three vulnerable Windows drivers to disable security software.
  • The attackers finished the job by installing ValleyRAT, also called Winos 4.0, a tool that gives them long-term remote control of the machine.
  • Two of the drivers had not been seen abused this way before, expanding the pool of "trusted" software that criminals can turn against defenders.
  • The technique is called BYOVD, short for Bring Your Own Vulnerable Driver, and it works because Windows still trusts signed drivers even when they're known to be broken.

A Chinese hacking crew called Silver Fox has been caught breaking into a Japanese factory by loading old, flawed Windows drivers onto the company's systems and using them to switch off security tools.

Once the alarms were silenced, the attackers installed ValleyRAT, a remote-access trojan: a program that lets criminals control a computer from anywhere as if they were sitting at the keyboard. It's also known as Winos 4.0. The campaign was first reported by The Hacker News, based on research into a single victim in Japan's industrial manufacturing sector.

We covered Silver Fox dropping a different payload, MODBEACON, inside fake software installers on 10 July. That campaign relied on booby-trapped downloads; this one weaponises the Windows driver stack instead.

What is a "vulnerable driver" attack?

A driver is a small program that lets Windows talk to hardware like a printer or a graphics card. Drivers run deep inside the system with very high privileges, and Windows only trusts ones that carry a digital signature from a recognised vendor.

The problem: plenty of old signed drivers have known bugs. Drop one onto a machine and Windows still trusts it, letting an attacker use that bug to reach into the operating system's core. Security researchers call this Bring Your Own Vulnerable Driver, or BYOVD. It's like a burglar arriving in a legitimate uniform from a defunct security firm. The badge checks out. The person wearing it has no right to be there.

How did Silver Fox pull it off?

The group chained together three vulnerable drivers, two of which researchers say hadn't been seen abused in the wild before this campaign. Once loaded, the drivers were used to kill or blind the antivirus and endpoint-protection software running on the target machine.

With defences down, Silver Fox planted ValleyRAT for persistent access. Persistent access means the malware survives reboots and quietly phones home, giving the attackers a permanent back door into the factory's network.

Detail What we know
Attacker Silver Fox (China-linked cybercrime group)
Victim A Japanese industrial manufacturing firm
Technique BYOVD chain using three vulnerable drivers
Final payload ValleyRAT, also called Winos 4.0

Should ordinary people be worried?

Not directly. This attack targeted a specific company's machines rather than consumer devices, and it required the attackers to already have a foothold on the network before they could drop the drivers.

The wider concern is for anyone whose data sits inside industrial firms. If Silver Fox is inside a manufacturer's network for weeks or months, they can steal designs and payment details. Staff at affected companies should watch for unusual login prompts and phishing emails, where criminals send fake messages to trick people into handing over passwords.

Why this matters for defenders

BYOVD keeps working because Microsoft's driver blocklist, the official catalogue of known-bad drivers Windows should refuse to load, isn't updated fast enough and isn't switched on by default everywhere. Every new vulnerable driver Silver Fox adds to its toolkit is one more skeleton key that keeps working until Microsoft and antivirus vendors catch up.

ValleyRAT itself isn't new. We first covered it on 4 June, when TA4922 was deploying it against targets in the UK and Germany. Seeing the same payload now aimed at a Japanese manufacturer confirms what that story suggested: ValleyRAT is becoming a shared tool across China-linked clusters, not a signature of any single group. The geography is shifting. That's what to watch.

© 2026 Threat Vectr