WatchDog Used in Cyber Attacks by Silver Fox Targeting East Asia

02 Sep 2025

The threat actor known as Silver Fox has been identified as exploiting the WatchDog antimalware driver, specifically version 1.0.600 of amsdk.sys, to compromise various systems in East Asia. This driver, trusted due to its origin from legitimate software, was leveraged to disable antivirus and Endpoint Detection and Response (EDR) systems, allowing attackers to implant their ValleyRAT malware unhindered.

Attack Strategy and Execution

Silver Fox's modus operandi involved using the driver to terminate security processes on the targeted devices. The vulnerability exploited allowed them to open backdoors, providing a gateway for the remote execution of commands and data theft. ValleyRAT, the malware of choice in these operations, enabled Silver Fox to maintain control over compromised devices effectively.

Additionally, to ensure their attack could span across various Windows platforms, Silver Fox made use of another anti-malware driver from Zemana, known as ZAM.exe. This strategic move ensured the compatibility and efficacy of their tools across different system configurations.

Delivery and Deployment

According to Check Point Research, the attackers have been identified as leveraging a robust infrastructure based in China to host their self-contained loader binaries. These loaders not only incorporated anti-analysis features to evade detection but were also equipped with persistence mechanisms. Integral to this setup were both the WatchDog and Zemana drivers, alongside a hardcoded registry of security processes marked for termination.

The attack vector likely followed through traditional means such as phishing or social engineering, methods commonly employed to gain initial access to the systems by deceiving unsuspecting users.

Preventive Measures and Recommendations

In response to these sophisticated attacks, WatchDog has released an update addressing the local privilege escalation flaw present in the driver. However, it is important to note that the risk of arbitrary process termination remains a concern. To counteract this vulnerability, Check Point Research has recommended several key measures that IT departments should adopt.

  • First, updating driver blocklists is crucial to prevent the exploitation of such vulnerabilities.
  • Second, deploying YARA detection rules will aid in identifying and mitigating threats quickly.
  • Lastly, continuous monitoring of networks and endpoints for signs of suspicious activity and traffic is advised, ensuring that any anomalies are detected and nullified promptly.

By implementing these strategies, organizations can bolster their defenses against cyber threats similar to those orchestrated by Silver Fox, safeguarding their critical systems and sensitive data from being compromised.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6339647
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1251030
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
492617
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452986
downloads

News and reviews for Desktop Windows

Five New Steam Games Released: Notable Titles for November 2025

Explore five new Steam games launched in late October 2025, ranging from narrative adventures to twin-stick shooters and trading simulations.

Read more

Mortal Kombat: Legacy Kollection Faces Early Challenges on Steam

Mortal Kombat: Legacy Kollection launched on Steam with issues, including input lag and online problems. Patches are underway to address concerns.

Read more

Arc Raiders Strains Under Surge of Players

Arc Raiders faces login queues and matchmaking issues as concurrent players spike to 337,834.

Read more

Flyoobe Users Alerted to Potential Malware via Fake Site

Flyoobe users advised to avoid fake site amid security risks. Verify downloads from official channels to prevent malware.

Read more

Diablo 2 Update: New Ammo Types Enhance Ranged Combat

Project Diablo 2 Season 12 adds diverse ammo types, enhancing ranged combat with arrows and bolts. Date to be confirmed during November 8 stream.

Read more

Resonance Solstice Faces Mixed Reviews at Launch

Resonance Solstice, a free Steam game, launched with mixed feedback. Player concerns focus on complex currencies and gameplay mechanics.

Read more

Thief VR Set for December Release with Promising Features

Thief VR: Legacy of Shadow, launching 2025-12-04, introduces new protagonist Magpie with immersive gameplay changes.

Read more

EDR-Redir V2 Bypasses Windows Defender with Redirection Loops

EDR-Redir V2 uses fake program files to evade Windows Defender on Windows 11, exploiting directory redirection tactics.

Read more

Office 2021 Lifetime License Discounted to $39.97

For a limited time, purchase Office 2021 for $39.97, a significant discount from its usual $219.99 price.

Read more

Spooky Express Update Brings Over 200 New Levels

Spooky Express, by Draknek and Friends, expands Cosmic Express with 200+ levels, now on Steam.

Read more