{"id":10870,"date":"2026-02-23T10:04:02","date_gmt":"2026-02-23T10:04:02","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/23\/silver-fox-apt-uses-dll-sideloading-and-byovd-techniques-in-sophisticated-malware-attacks\/"},"modified":"2026-02-23T10:04:02","modified_gmt":"2026-02-23T10:04:02","slug":"silver-fox-apt-uses-dll-sideloading-and-byovd-techniques-in-sophisticated-malware-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/23\/silver-fox-apt-uses-dll-sideloading-and-byovd-techniques-in-sophisticated-malware-attacks\/","title":{"rendered":"Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks"},"content":{"rendered":"<p>    Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. <\/p>\n<p>This operation focuses heavily on Asia, targeting local organizations with carefully localized lures. <\/p>\n<p>By disguising attacks as routine business communications, actors successfully distributed the Winos 4.0 malware, known as ValleyRat, into corporate networks.<\/p>\n<p>To compromise victim systems, attackers leverage deceptive <a href=\"https:\/\/cybersecuritynews.com\/hr-it-related-phishing-emails-are-top-clicked\/\" id=\"85221\" target=\"_blank\" rel=\"noreferrer noopener\">phishing emails<\/a> containing malicious attachments or embedded links. <\/p>\n<p>These messages closely impersonate official government correspondence, such as tax audit notifications, software installers, and electronic invoice downloads.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjfOq2dwewTUAoJgeLdpzhYURy8Ycd76TvuKF8yUbQyiC4aFWaXbqvY9qqunlDIg8gSsrMKSFPRQTrGI5pm13lRwAf3HaPjgMJZPK-bJXebb1cKcv9E21ZkEE4M0ry1bF8iQZ3KL0KqR4U-J-_tL2IgP2xVK7-sTxJRv4X_Ysx8GWA9Lbyzk7ww50dLsy0\/s16000\/Tax-themed%2520phishing%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Tax-themed phishing (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>When a user interacts with these files, they trigger a complex infection chain that operates quietly, minimizing the chances of immediate user suspicion.<\/p>\n<p>The final impact of a successful infection is severe, leading to widespread file encryption and extensive <a href=\"https:\/\/cybersecuritynews.com\/russian-hacker-sentenced-for-data-theft-of-linkedin-dropbox-users\/\" id=\"3710\" target=\"_blank\" rel=\"noreferrer noopener\">data theft<\/a> that can fuel further cyberattacks. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjpPZsvtCH5CEXntQI5q4pz2D9kzKcwUwuVZvU9et942fCP20Mc4jN-4Ue6WOYe1pd0LFAqCv7zmv3bIShuqbLmm47iqHZn2b5dXhVzcmWr3U8inHhLrNLiUK7EacScUcR0HLZYO67YYfzi4r-J-2s1YJb-HwqMO-C9JCHs6Sx7NZsfxb2wo-LmMjKhyaA\/s16000\/Attacker%25E2%2580%2599s%2520domain%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"Attacker\u2019s domain (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">Attacker\u2019s domain (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p><a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/massive-winos-40-campaigns-target-taiwan\" id=\"https:\/\/www.fortinet.com\/blog\/threat-research\/massive-winos-40-campaigns-target-taiwan\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fortinet researchers identified the malware<\/a> and its infrastructure as highly volatile, utilizing a rotating network of cloud domains to host their payloads. <\/p>\n<p>This rapid shifting of resources makes traditional static domain blocking mostly ineffective as a primary defense measure against the ongoing Winos 4.0 operations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-advanced-detection-evasion-techniques\"><strong>Advanced Detection Evasion Techniques<\/strong><\/h2>\n<p>Once inside a network, the Silver Fox group employs advanced detection evasion strategies to maintain access and control. <\/p>\n<p>The attackers deliver an archive containing a legitimate application that secretly sideloads a malicious dynamic link library into memory.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEivSYzURGan0OlmLeinxabV_CMusa7XfdUfVIeDtWNfM4K4Tc9kS3JjcfoSif_UHHHANhdZ_MmfUk7C9ze6oLI_hPG85IHCfMyKBMxGgxR1I5szCiCy0ZT97jsPV_F1iGYBGdEnYw2GN6vek9urgNUzRBgZ47QEWxzOqvSUBXOBJZ5PK-TwxDedPi4ZS_E\/s16000\/The%2520execution%2520file%2520and%2520the%2520malicious%2520DLL%2520file%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"The execution file and the malicious DLL file (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">The execution file and the malicious DLL file (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>This stage sets the foundation for a \u201cBring Your Own Vulnerable Driver\u201d attack. The malware loads a validity-signed Windows kernel-mode driver, named wsftprm.sys, to silently acquire elevated <a href=\"https:\/\/cybersecuritynews.com\/teamviewer-windows-app-let-attackers-escalate-privileges\/\" id=\"90626\" target=\"_blank\" rel=\"noreferrer noopener\">system privileges<\/a> without alerting administrators.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh9QwHCgnAIke_k0mlzUCWE258pVxsNo7-cnqDYlEXNstDzdXAzTJ55pvYGgBR5xN1HM-YeP3hEE5AvhnCnDf7SGVNgHQRzqwmfXYsaGSNFYifyz35B9NjprTA6BiY3dLUDRLodw1yaKnOBHzUnGeAGNfmx-t4gi2fdjsdiyUkcDnvZ4I-lyP3KMUAgkYI\/s16000\/Archive%2520contents%2520with%2520LNK%2520and%2520social-engineering%2520decoys%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"Archive contents with LNK and social-engineering decoys (Source - Fortinet)\"><figcaption class=\"wp-element-caption\">Archive contents with LNK and social-engineering decoys (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>After securing kernel-level access, the malicious driver enters a continuous monitoring loop to identify and terminate active security processes. <\/p>\n<p>By targeting a vast array of popular antivirus and <a href=\"https:\/\/cybersecuritynews.com\/ransomware-protection-tools\/\" id=\"17133\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint protection tools<\/a>, the malware creates a completely blind environment. This allows Winos 4.0 to operate, escalate its privileges, and maintain remote communication with its command server unimpeded.<\/p>\n<p>To effectively defend against these highly sophisticated techniques, organizations must treat all unexpected documents and external links with extreme caution. <\/p>\n<p>Security teams should implement behavioral monitoring tools, continuously update endpoint protection signatures, and deploy strong email filtering solutions to proactively detect evasive phishing attempts before they occur.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/silver-fox-apt-uses-dll-sideloading\/\">Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/silver-fox-apt-uses-dll-sideloading\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. This operation focuses heavily on Asia, targeting local organizations with carefully localized lures. By disguising attacks as routine business communications, actors successfully distributed the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10870","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10870"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10870"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10870\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}