Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Malware - Silver Fox Exploits Signed Drivers to Deliver ValleyRAT
Malware Attacks Latest News News & Analysis Security Threats and Vulnerabilities

Silver Fox Exploits Signed Drivers to Deliver ValleyRAT

Kirsten DoyleBy Kirsten DoyleSeptember 2, 2025Updated:September 2, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Silver Fox Exploits1
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Check Point Research has uncovered a new campaign tied to the Silver Fox APT group. The operation relies on signed but vulnerable Windows drivers to slip through security defenses and deliver ValleyRAT, a modular backdoor. 

Two drivers are key to this operation, both built on the Zemana Anti-Malware SDK. One is old and already flagged and blocked on most systems, while the other is new, still trusted, and signed by Microsoft.  

That signature means it loads without question, even on fully updated Windows 10 and 11 machines. Both drivers share the same ability: they can terminate protected processes, the very ones meant to guard against attack. 

The loader is compact and carries everything it needs. It slips in through .rar archives or disguised DLLs. Once inside, it chooses the right driver for the operating system and clears away the defenses. After that, ValleyRAT is delivered. 

The backdoor is versatile, running in memory, injected into existing processes, and communicates with servers hosted in China. It can steal data, execute commands, and watch its environment. To help with obfuscation, it checks for analysis tools, delaying its work if it suspects a sandbox is present. Cunningly, it waits until the coast is clear. 

Silver Fox has revealed how quickly it is able to adapt. When Watchdog patched its driver, the group took the new version and changed a single byte in its digital timestamp. The alteration was so subtle, it didn’t break the Microsoft signature, so Windows continued to trust it. Yet the hash changed, which was enough to enable it to slip past blocklists that rely on hashes alone. 

This is the edge attackers work on: a signed driver that looks safe, and a patch that looks complete. Yet both can be bent into weapons with little effort. Researchers confirmed the WatchDog driver carried multiple flaws, from local privilege escalation to raw disk access. The patch closed some holes but left others wide open, including the ability to kill processes used by security tools. 

The malware targets security products common in China, and its infrastructure is also hosted there. Victims are spread across several regions, but the campaign’s design suggests its primary focus is close to home. 

Check Point has noticed a pattern that goes beyond Silver Fox. More groups are turning to signed but vulnerable drivers. They know that Microsoft’s blocklist is updated only once or twice a year and that gaps exist. They also know defenders still place too much trust in a signature. 

Closing that gap requires layered defenses. YARA rules can help identify malicious drivers, and manual updates to blocklists can add coverage. However, the most important shift is toward behavior-based detection, which looks past trust labels and focuses on what software actually does. 

Silver Fox has shown how fragile trust can be and that a valid signature does not guarantee safety. Defenders need to watch how drivers behave, not just who signed them. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access
  • Kirsten Doyle
    Major US telecom providers debut C2 ISAC to counter AI-driven threats

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

When PUPs bite: Huntress uncovers “weaponised” adware exposing 25,000+ systems

April 16, 20262 Mins Read

Fake Tech Support Scams Deliver Advanced Command-and-Control Malware

March 5, 20262 Mins Read

Americans Lost Over $20 million in ATM “Jackpotting” Attacks

February 24, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}