Actor Profile
Silver Fox is a Chinese cybercrime group known for sophisticated intrusion campaigns targeting organizations in Asia. The group demonstrates advanced operational capabilities through multi-layered attack chains combining BYOVD techniques, DLL side-loading, and custom RAT deployment. Silver Fox is motivated by persistent remote access to victim networks, leveraging modular frameworks that enable operational resilience and evasion of security controls. The group actively refines its arsenal with tools including ValleyRAT (Winos 4.0), Atlas RAT (AtlasCross RAT), RomulusLoader, SilentRunLoader, Gh0st RAT, and DCRat.
TTPs (Tactics, Techniques, Procedures)
The campaign employs a sophisticated multi-stage attack chain beginning with invoice-themed phishing (T1566.001) leveraging legitimate QQ and Tencent Cloud infrastructure. Initial access delivers a ZIP archive containing a downloader that retrieves next-stage components for DLL side-loading (T1574.002) via legitimate Zeon Corporation binaries (ConvertToPDF.exe, PDFDirect.exe). The malicious DLL (PDFCORE8.dll) embeds three vulnerable drivers (BootRepair.sys, EnPortv.sys, wsftprm.sys) for BYOVD attacks (T1068) to obtain kernel access and impair defenses (T1562.001). NTDLL unhooking removes user-mode inline hooks from endpoint security software. Process injection via thread-context hijacking (T1055.003) delivers shellcode into svchost.exe. Persistence mechanisms include scheduled tasks (T1053.005) and registry-based payload storage. A dual watchdog design ensures execution recovery through coordinated internal and external monitoring components. C2 communication with external infrastructure (43.128.26[.]132) enables remote access and post-compromise operations.
Targets & Patterns
Silver Fox targets organizations in the industrial manufacturing sector, with this campaign specifically focused on a Japanese manufacturer. The group also operates against targets in China. The selection of industrial manufacturing suggests interest in intellectual property, operational technology environments, or supply chain positioning. The use of invoice-themed phishing lures indicates targeting of finance, procurement, or administrative personnel as initial access vectors. The group's broader campaign patterns include tax-themed lures, suggesting opportunistic targeting of organizations during financial reporting periods. The geographic focus on Japan and China aligns with regional cybercrime operations and potential economic espionage objectives.
Historical Context
Silver Fox has previously employed BYOVD techniques using the vulnerable drivers amsdk.sys and wsftprm.sys. The current campaign represents an evolution with the introduction of two newly observed drivers (BootRepair.sys and EnPortv.sys), demonstrating the group's commitment to operational resilience through modular, plug-and-play driver frameworks. Recent activity shows the group expanding its malware arsenal with Atlas RAT (AtlasCross RAT), RomulusLoader, and SilentRunLoader. A 180-day VirusTotal retrohunt identified 146 unique Atlas RAT samples spanning six versioned PDB builds, two development environment usernames, and 27 heuristic lineages, suggesting possible commercial development or private distribution rather than single-operator management. The group continues parallel campaigns using tax-themed lures to deliver Gh0st RAT and DCRat, indicating sustained operational tempo across multiple intrusion sets.
Defensive Recommendations
- Monitor for DLL side-loading activity involving legitimate signed binaries (ConvertToPDF.exe, PDFDirect.exe from Zeon Corporation) loading unexpected DLLs from non-standard paths (T1574.002)
- Implement driver load monitoring and block known vulnerable drivers (BootRepair.sys, EnPortv.sys, wsftprm.sys, amsdk.sys) via Windows Defender Application Control or similar driver signature enforcement policies
- Detect NTDLL unhooking attempts through monitoring for suspicious memory modifications to ntdll.dll in process memory, particularly WriteProcessMemory calls targeting NTDLL address space
- Hunt for thread-context hijacking (T1055.003) by monitoring for suspicious thread creation in legitimate processes like svchost.exe, especially when preceded by SetThreadContext API calls
- Block or monitor outbound connections to Tencent Cloud infrastructure used for staging (43.128.26[.]132) and implement behavioral detection for scheduled tasks (T1053.005) created by non-administrative processes with watchdog script characteristics
---
# Geopolitical Context
Geopolitical Context
The campaign reflects ongoing cyber-enabled economic espionage and intellectual property targeting consistent with regional strategic competition in East Asia. Chinese-nexus threat actors have historically demonstrated sustained interest in Japanese industrial and manufacturing sectors, which represent critical nodes in regional supply chains and advanced technology development. The use of sophisticated multi-layered evasion techniques—including a three-driver BYOVD framework and dual watchdog persistence mechanisms—indicates operational maturity and resource investment consistent with financially motivated cybercrime groups that may operate with varying degrees of state tolerance. While Silver Fox is characterized as a cybercrime group rather than a state-sponsored APT, the targeting of strategic industrial sectors in a geopolitical rival aligns with broader patterns of Chinese cyber activity against Japanese economic interests amid ongoing territorial disputes and technology competition.
State Actor Alignment
Silver Fox is assessed to be a Chinese cybercrime group rather than a state-sponsored advanced persistent threat (APT). However, the group's targeting of Japanese industrial manufacturing—a sector of strategic economic and technological significance—raises questions about the operational boundaries between financially motivated cybercrime and state-tolerated activity. Chinese authorities have historically demonstrated selective enforcement against domestic cyber actors, particularly when their operations align with broader national interests or target geopolitical competitors. No direct state attribution or sanctions designation has been publicly reported for Silver Fox. The group's use of Chinese infrastructure (QQ, Tencent Cloud) and focus on regional targets suggests operations conducted from within China's jurisdiction, though this does not necessarily indicate formal state sponsorship or direction.
Business Impacty pro region
The targeting of Japanese industrial manufacturing has direct implications for regional supply chain security and economic competitiveness in the Indo-Pacific. Japan's manufacturing sector is deeply integrated into global technology supply chains, particularly in semiconductors, automotive systems, and advanced materials. Compromise of these entities could enable intellectual property theft, supply chain manipulation, or pre-positioning for future disruptive operations. For European partners with significant manufacturing investments in Japan or supply chain dependencies on Japanese industrial output, this campaign underscores shared vulnerabilities in the global manufacturing ecosystem. The incident may reinforce Japanese government efforts to strengthen cybersecurity requirements for critical infrastructure and industrial base protection, potentially influencing regulatory approaches in allied nations. The campaign also highlights the persistent challenge of distinguishing between state-sponsored and state-tolerated cyber operations originating from China, complicating diplomatic and defensive responses.
Forecast
If Silver Fox continues to refine its multi-driver BYOVD capabilities and expand its toolset (including Atlas RAT, RomulusLoader, and SilentRunLoader), additional targeting of Japanese and regional manufacturing entities is likely in the near term. The group's operational tempo and tool diversity suggest either a well-resourced single operation or a potential malware-as-a-service model serving multiple operators, which could broaden the threat surface. If Japanese authorities or international partners impose costs through law enforcement action or public attribution, Silver Fox may temporarily reduce visible activity or shift infrastructure, though sustained operational disruption appears unlikely without addressing hosting infrastructure in China. If the group's activities continue to align with strategic Chinese interests without enforcement action by Chinese authorities, this may fuel broader policy debates in Japan and allied nations regarding the state-tolerance model and appropriate response measures. Defenders should anticipate continued abuse of legitimate software for DLL side-loading and evolution of BYOVD techniques as security vendors adapt detections.
