Threat actors in multiple intrusions abused Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint protections from kernel mode after gaining access through phishing or compromised remote-access credentials. Huntress reported an intrusion that began with stolen SonicWall SSLVPN credentials and escalated into deployment of an EDR killer built around a legitimate EnCase forensic driver, which Windows loaded despite the driver’s expired and revoked certificate. The malware hid the embedded driver with a 256-word substitution scheme, installed it as a kernel service with OEM-like naming, and repeatedly terminated a hashed list of 59 security processes before responders disrupted the attack ahead of ransomware deployment.
Separate research tied similar tradecraft to SilverFox, which used vulnerable or signed drivers including BootRepair.sys, EnPortv.sys, wsftprm.sys, and a Microsoft-signed WatchDog Antimalware driver derived from the Zemana SDK to kill protected security processes and deliver ValleyRAT/Winos. Cato documented a campaign against a Japanese industrial manufacturer that used invoice-themed phishing, abused QQ and Tencent Cloud for delivery, and sideloaded a malicious PDFCORE8.dll through legitimate ConvertToPDF.exe and **PDFDirect.exe`; Check Point found SilverFox also adapted quickly to blocklists by modifying a single byte in an unauthenticated Authenticode timestamp area, preserving a valid Microsoft signature while changing the file hash. The combined reporting shows attackers increasingly pairing initial access with signed-driver abuse, DLL sideloading, and stealthy loaders to neutralize EDR before establishing persistent remote access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Cato assessed with moderate-to-high confidence that the activity was linked to SilverFox based on tooling, execution flow, infrastructure, victimology, and the FaCai2024 marker. It also said its platform blocked the malicious PDFCORE8.dll before ValleyRAT established remote access.
Cato Networks described an active SilverFox campaign against a Japanese industrial manufacturing organization that used an invoice-themed phishing lure, abused QQ and Tencent Cloud services, and DLL sideloading via ConvertToPDF.exe and PDFDirect.exe to load a malicious PDFCORE8.dll.
AhnLab ASEC published analysis of AtlasRAT as a Windows RAT delivered through a four-stage in-memory loader chain beginning with a Delphi executable disguised as AGE Flash Player and ending in a modular DLL payload. The report described TLS-based ChaCha20-encrypted C2, plugin execution, offline keylogging, WeChat DLL injection, and said any connection to Silver Fox was only circumstantial and not confirmed.
Further reporting on the Japanese manufacturer intrusion revealed SilverFox used a modular three-driver BYOVD framework with newly observed BootRepair.sys and EnPortv.sys, alongside DLL sideloading and registry-stored payloads to deploy ValleyRAT. The malware also used dual watchdog recovery mechanisms so the loader and injected payload could restore each other if one was terminated.
Huntress correlated SonicWall telemetry with endpoint detections, quarantined affected systems, and disrupted the intrusion before the attackers could deploy ransomware.
After gaining access, the attackers performed reconnaissance and deployed an EDR killer that used a BYOVD technique with a legitimate Guidance Software EnCase forensic driver to terminate security tools from kernel mode and persist as a kernel service.
In early February 2026, Huntress investigated an intrusion that began when threat actors used compromised SonicWall SSLVPN credentials to gain access to a victim network.
Following the patched driver release, the attackers adapted by using a modified variant of the patched driver. They altered a single byte in the unauthenticated Authenticode timestamp area to preserve the Microsoft signature while changing the file hash to bypass hash-based blocklists.
After disclosure of the vulnerable WatchDog driver abuse, the vendor released wamsdk.sys v1.1.100. The patch fixed a local privilege escalation issue but still allowed arbitrary process termination.
Check Point Research reported an in-the-wild Silver Fox campaign that abused a previously unclassified Microsoft-signed WatchDog Antimalware driver (amsdk.sys v1.0.600) to disable endpoint protections and deploy the ValleyRAT remote access trojan on fully updated Windows 10/11 systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourceasec.ahnlab.com
Open sourcecatonetworks.com
Open sourceresearch.checkpoint.com
Open sourcepicussecurity.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.