logo

'Silver Fox' APT Skirts Windows Blocklist in BYOVD Attack

ID: 41597207-49b3-552e-9f86-4694035dcc22

STIX ID: report--41597207-49b3-552e-9f86-4694035dcc22

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-02-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Chinese cybercriminal group "Silver Fox" exploited a legacy Windows driver (Truesight.sys v2.0.2) that incorrectly escaped Microsoft's vulnerable-driver blocklist, enabling bring-your-own-vulnerable-driver (BYOVD) attacks to terminate protected AV/EDR processes and deploy Gh0stRAT across targets primarily in China and Southeast Asia; the report warns this represents a broader risk because many legitimate drivers contain exploitable flaws at the kernel level.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.