# The Kill Switch That Isn't: SilverFox's Three-Driver BYOVD Framework Is Built to Outlast Your Incident Response
When a SOC analyst terminates a suspicious process, they're usually done. Threat contained, ticket closed, coffee gets reheated. SilverFox has spent considerable engineering effort making that assumption lethal.
The Chinese cybercrime group's latest campaign — uncovered by Cato Networks researchers targeting an unnamed Japanese industrial manufacturer — doesn't just deploy BYOVD to blind endpoint security. It deploys a self-healing, dual-watchdog persistence framework specifically designed for the moment your defenders think they've won.
## The Architecture of Survival
The attack opens with an invoice-themed phishing lure, a perennial classic, but the delivery mechanism is where things get interesting. The ZIP payload retrieves components from attacker-controlled Tencent Cloud infrastructure — legitimate cloud services that slide through network controls because they share infrastructure with half of East Asia's legitimate traffic. A DLL sideloading chain then executes through ConvertToPDF.exe or PDFDirect.exe, both legitimate binaries signed by Zeon Corporation.
From there, a malicious DLL named PDFCORE8.dll unpacks three vulnerable kernel drivers:
The three-driver design isn't redundancy in the traditional sense. It's modularity. The operators can swap individual drivers as they're flagged or added to blocklists without rebuilding the rest of the execution chain. It's plug-and-play BYOVD — an attacker-side package management system for kernel exploits.
Once kernel access is obtained, the malware strips out NTDLL inline hooks — the user-mode tripwires that EDR products install to monitor native Windows API calls. With those gone, subsequent activity is largely invisible to security tooling watching from userland.
## The Part That Should Bother Defenders Most
Thread-context hijacking injects the final payload — ValleyRAT, a Gh0st RAT derivative with full C2 capability — into a freshly spawned svchost.exe process. That's not unusual. What Silver Fox has built around it is.
The dual watchdog design works like this: an internal routine inside the injected payload monitors its own execution. If the payload dies, the loader brings it back. If defenders terminate the loader instead, an external watchdog batch script — persisted via scheduled task and phoning home to 43.128.26[.]132 — relaunches the loader.
To fully evict this implant, a defender must terminate both components before either can restore the other. In practice, under time pressure, against an alert that reads "svchost.exe," that's harder than it sounds. The batch script is a race condition deliberately engineered into the attack.
Payload storage in the registry adds another layer: there's nothing on disk to delete.
## ValleyRAT's Target Profile
ValleyRAT (also tracked as Winos 4.0) has a documented history against Chinese-speaking targets and has been observed in campaigns hitting education, manufacturing, and trading sectors. Its appearance here against a Japanese industrial manufacturer fits a broader pattern of Chinese threat actors pivoting from domestic targets to regional industrial competitors — particularly in manufacturing verticals where intellectual property theft has direct commercial value.
Japanese manufacturers represent a specific strategic target class: sophisticated enough to have meaningful IP, integrated into global supply chains that give attackers lateral movement options, and historically underinvested in enterprise-grade security compared to their US counterparts.
The use of Tencent Cloud and QQ infrastructure for hosting also complicates attribution for defenders relying on geographic or ASN-based blocking. Blocking Tencent cloud ranges is a real operational decision with real business costs for organizations with legitimate Asia-Pacific operations.
## What the Defender Checklist Misses
The standard BYOVD countermeasure is driver blocklisting — Microsoft's HVCI vulnerable driver blocklist, third-party feeds, hash-based detections. Silver Fox's answer is to swap drivers faster than blocklists update, and to source drivers that haven't yet been publicly reported. BootRepair.sys and EnPortv.sys weren't on anyone's radar before this campaign.
Registry-based payload storage defeats file-based AV scanning. NTDLL unhooking defeats user-mode EDR hooks. The dual watchdog defeats single-process termination. This is a campaign designed by people who have read the defender playbook and worked around each chapter.
---
## HackWire Analysis
Silver Fox's three-driver BYOVD framework represents something the security industry should talk about more plainly: BYOVD has matured from a clever technique into an engineering discipline. The shift from single-driver abuse to a modular, swappable multi-driver system signals that this isn't improvised malware — it's maintained software with a release cycle.
The dual watchdog design deserves particular attention because it specifically targets incident response procedure, not just security tooling. It's built for the human latency in a SOC: the moment between "I killed the suspicious process" and "I'm going to check if there's something else running." SilverFox is betting that defenders, under pressure, will declare victory after the first termination. They've structured their malware to survive that assumption.
Pattern-match this against the broader Chinese threat actor landscape and a clear theme emerges: persistent access over destructive impact. Groups like APT41, Winnti, and now SilverFox are investing in tools that stay quiet and stay running. ValleyRAT's post-compromise capabilities aren't flashy — they're durable. The goal appears to be long-duration presence in industrial manufacturing environments, which is consistent with strategic IP collection rather than ransomware or disruption.
For defenders, the actionable signal here is to stop treating BYOVD as a checkbox on an EDR vendor's feature sheet. Kernel driver telemetry, scheduled task creation alerts, and behavioral detection of NTDLL unhooking need to be live, not aspirational. More importantly: when you terminate a suspected implant, verify the loader is also gone. Silver Fox is counting on you not to.
— HackWire Editorial
---
## Related Coverage