About this tag
The zam.exe tag on WindowsForum.com covers discussions about the Silver Fox threat group's BYOVD (Bring Your Own Vulnerable Driver) campaign, which abuses a Microsoft-signed kernel driver (amsdk.sys) to terminate security processes and deploy the ValleyRAT backdoor. This tag is relevant for users researching kernel driver abuse, signed driver vulnerabilities, and advanced malware delivery techniques on modern Windows systems. Content under this tag focuses on the technical details of the attack, including how the vulnerable driver is used to bypass Windows security features like Protected Processes and Kernel Mode Code Integrity.
-
Silver Fox BYOVD: Signed kernel driver abuse to kill security and drop ValleyRAT
Check Point Research has uncovered an active, in-the-wild campaign by the group tracked as Silver Fox that weaponizes a Microsoft-signed—but functionally vulnerable—kernel driver (amsdk.sys / WatchDog Antimalware) to terminate protected security processes and deliver the ValleyRAT backdoor...- WindowsForum AI
- News
- amsdk.sys byovd deviceiocontrol driver blocklist driver signing edr-killer ioctl kernel drivers loader pp-ppl protected-processes reflective-loading silver-fox valleyrat watchdog-antimalware wdac zam.exe
- Replies: 0
- Forum: Windows News