#valleyrat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #valleyrat, aggregated by home.social.
-
Discover how the SilverFox ValleyRAT attack leverages fake invoices and DLL side-loading to bypass defenses and target Japanese industrial firms.
#SilverFox #ValleyRAT #Cybersecurity #PhishingAttack #MalwareAnalysis
https://meterpreter.org/silverfox-valleyrat-attack/?utm_source=mastodon&utm_medium=jetpack_social
-
Discover how the SilverFox ValleyRAT attack leverages fake invoices and DLL side-loading to bypass defenses and target Japanese industrial firms.
#SilverFox #ValleyRAT #Cybersecurity #PhishingAttack #MalwareAnalysis
https://meterpreter.org/silverfox-valleyrat-attack/?utm_source=mastodon&utm_medium=jetpack_social
-
📰 SilverFox APT Hits Japanese Manufacturer with Advanced ValleyRAT
Chinese APT group SilverFox targets Japanese manufacturer with a sophisticated version of ValleyRAT. The campaign uses phishing, DLL sideloading, and vulnerable kernel drivers for stealthy, persistent access and espionage. #APT #ThreatIntel #ValleyRAT
-
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign Pierluigi Paganini July 31, 2026 SilverFox targeted a Japanese manufacturer…
#EuropeSays #Japan #JP #apt #china #hacking #hackingnews #informationsecuritynews #ITInformationSecurity #Japanese #malware #PierluigiPaganini #SecurityAffairs #SecurityNews #SilverFox #ValleyRAT
https://www.europesays.com/japan/66885/ -
Cato CTRL details a new SilverFox ValleyRAT campaign in Japan using three BYOVD drivers and DLL sideloading to kill security tools.
#SilverFox #ValleyRAT #BYOVD #Winos40 #DLLSideloading #Malware #ThreatIntel #Cybersecurity
-
LevelBlue tracks a ValleyRAT malware email campaign using DLL sideloading and fileless execution to hit Japanese and Chinese users.
-
LevelBlue tracks a ValleyRAT malware email campaign using DLL sideloading and fileless execution to hit Japanese and Chinese users.
-
VBScript via WhatsApp: documenti aziendali falsi installano ManageEngine RMM in campagna globale con tracce cinesi
Kaspersky documenta una campagna malware attiva in 11 Paesi che usa WhatsApp per distribuire VBScript offuscati camuffati da documenti aziendali. Il payload finale è ManageEngine Endpoint Central, riconfigurato per il controllo remoto. L'infrastruttura mostra sovrapposizioni con Gh0st RAT e ValleyRAT. -
VBScript via WhatsApp: documenti aziendali falsi installano ManageEngine RMM in campagna globale con tracce cinesi
Kaspersky documenta una campagna malware attiva in 11 Paesi che usa WhatsApp per distribuire VBScript offuscati camuffati da documenti aziendali. Il payload finale è ManageEngine Endpoint Central, riconfigurato per il controllo remoto. L'infrastruttura mostra sovrapposizioni con Gh0st RAT e ValleyRAT. -
VBScript via WhatsApp: documenti aziendali falsi installano ManageEngine RMM in campagna globale con tracce cinesi
Kaspersky documenta una campagna malware attiva in 11 Paesi che usa WhatsApp per distribuire VBScript offuscati camuffati da documenti aziendali. Il payload finale è ManageEngine Endpoint Central, riconfigurato per il controllo remoto. L'infrastruttura mostra sovrapposizioni con Gh0st RAT e ValleyRAT. -
VBScript via WhatsApp: documenti aziendali falsi installano ManageEngine RMM in campagna globale con tracce cinesi
Kaspersky documenta una campagna malware attiva in 11 Paesi che usa WhatsApp per distribuire VBScript offuscati camuffati da documenti aziendali. Il payload finale è ManageEngine Endpoint Central, riconfigurato per il controllo remoto. L'infrastruttura mostra sovrapposizioni con Gh0st RAT e ValleyRAT. -
VBScript via WhatsApp: documenti aziendali falsi installano ManageEngine RMM in campagna globale con tracce cinesi
Kaspersky documenta una campagna malware attiva in 11 Paesi che usa WhatsApp per distribuire VBScript offuscati camuffati da documenti aziendali. Il payload finale è ManageEngine Endpoint Central, riconfigurato per il controllo remoto. L'infrastruttura mostra sovrapposizioni con Gh0st RAT e ValleyRAT. -
TA4922: The Suspected Chinese Crime Group is Going Global
#TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #ValleyRAT
https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global -
TA4922: The Suspected Chinese Crime Group is Going Global
#TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #ValleyRAT
https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global -
TA4922: The Suspected Chinese Crime Group is Going Global
#TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #ValleyRAT
https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global -
Una riunione urgente su Teams e il conto svuotato: la nuova truffa che sfrutta il panico da videocall
C’è un dettaglio interessante nelle nuove campagne cyber che stanno circolando nelle ultime ore: non cercano più di sembrare sofisticate. Cercano di sembrare normali. Una notifica su Microsoft Teams. Un collega che chiede supporto. Una call urgente prima di una riunione. E pochi minuti dopo, credenziali rubate, malware installato o conti aziendali compromessi. Tra le notizie emerse nelle ultime ore nel panorama cybersecurity internazionale, una delle più interessanti riguarda […] -
Una riunione urgente su Teams e il conto svuotato: la nuova truffa che sfrutta il panico da videocall
C’è un dettaglio interessante nelle nuove campagne cyber che stanno circolando nelle ultime ore: non cercano più di sembrare sofisticate. Cercano di sembrare normali. Una notifica su Microsoft Teams. Un collega che chiede supporto. Una call urgente prima di una riunione. E pochi minuti dopo, credenziali rubate, malware installato o conti aziendali compromessi. Tra le notizie emerse nelle ultime ore nel panorama cybersecurity internazionale, una delle più interessanti riguarda […] -
Una riunione urgente su Teams e il conto svuotato: la nuova truffa che sfrutta il panico da videocall
C’è un dettaglio interessante nelle nuove campagne cyber che stanno circolando nelle ultime ore: non cercano più di sembrare sofisticate. Cercano di sembrare normali. Una notifica su Microsoft Teams. Un collega che chiede supporto. Una call urgente prima di una riunione. E pochi minuti dopo, credenziali rubate, malware installato o conti aziendali compromessi. Tra le notizie emerse nelle ultime ore nel panorama cybersecurity internazionale, una delle più interessanti riguarda […] -
Silver Fox lancia ABCDoor: spear phishing con loader Rust personalizzato contro India e Russia, nuova backdoor Python in campo
Il gruppo APT cinese Silver Fox ha condotto campagne di spear phishing a tema fiscale contro organizzazioni in India e Russia, distribuendo il backdoor ValleyRAT affiancato da un nuovo payload Python inedito denominato ABCDoor. Kaspersky ha documentato il malware e le tecniche di evasione del loader RustSL, incluso il geofencing per paese e la persistenza tramite Phantom Persistence. -
Silver Fox lancia ABCDoor: spear phishing con loader Rust personalizzato contro India e Russia, nuova backdoor Python in campo
Il gruppo APT cinese Silver Fox ha condotto campagne di spear phishing a tema fiscale contro organizzazioni in India e Russia, distribuendo il backdoor ValleyRAT affiancato da un nuovo payload Python inedito denominato ABCDoor. Kaspersky ha documentato il malware e le tecniche di evasione del loader RustSL, incluso il geofencing per paese e la persistenza tramite Phantom Persistence. -
Silver Fox lancia ABCDoor: spear phishing con loader Rust personalizzato contro India e Russia, nuova backdoor Python in campo
Il gruppo APT cinese Silver Fox ha condotto campagne di spear phishing a tema fiscale contro organizzazioni in India e Russia, distribuendo il backdoor ValleyRAT affiancato da un nuovo payload Python inedito denominato ABCDoor. Kaspersky ha documentato il malware e le tecniche di evasione del loader RustSL, incluso il geofencing per paese e la persistenza tramite Phantom Persistence. -
📰 Fake LINE Messenger Installer Spreads ValleyRAT Malware
A fake LINE messenger installer is being used to spread ValleyRAT malware. The campaign, linked to the Silver Fox APT, targets Chinese-speaking users for credential theft. 🦊 #Malware #ValleyRAT #CyberSecurity
-
Fake Installer: Ultimately, ValleyRAT infection
#ValleyRAT
https://www.cybereason.com/blog/fake-installer-valleyrat -
Fake Installer: Ultimately, ValleyRAT infection
#ValleyRAT
https://www.cybereason.com/blog/fake-installer-valleyrat -
Fake Installer: Ultimately, ValleyRAT infection
#ValleyRAT
https://www.cybereason.com/blog/fake-installer-valleyrat -
#CheckPoint Research exposed #ValleyRAT’s modular system, including a kernel-mode #rootkit that can remain loadable on fully updated #Windows 11 despite built-in protections. The research linked leaked builder artifacts to plugins and identified about 6,000 samples, with roughly 85 percent emerging in the last six months after the builder’s public release.
https://research.checkpoint.com/2025/cracking-valleyrat-from-builder-secrets-to-kernel-rootkits/
-
#CheckPoint Research exposed #ValleyRAT’s modular system, including a kernel-mode #rootkit that can remain loadable on fully updated #Windows 11 despite built-in protections. The research linked leaked builder artifacts to plugins and identified about 6,000 samples, with roughly 85 percent emerging in the last six months after the builder’s public release.
https://research.checkpoint.com/2025/cracking-valleyrat-from-builder-secrets-to-kernel-rootkits/
-
New analysis reveals a Silver Fox operation using a fake Microsoft Teams installer to deploy ValleyRAT in attacks targeting China-based users.
The campaign mixes SEO poisoning, Cyrillic false-flag elements, DLL injection, and BYOVD techniques - making detection and attribution more challenging.
Researchers also note a secondary chain using a trojanized Telegram installer.
What’s your perspective on increased abuse of trusted-app installers in malware campaigns?
Source: https://thehackernews.com/2025/12/silver-fox-uses-fake-microsoft-teams.html
💬 Join the discussion
👍 Boost & follow for more threat intelligence#CyberSecurity #ThreatIntel #ValleyRAT #SilverFox #InfoSec #MalwareResearch #SecurityOps #CyberThreats
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
Mentioned Malware Families: ValleyRAT, PureRAT
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_rat
Aliases for PureRAT: win.pure_rat, PureHVNC, ResolverRAT
Malpedia link for PureRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.pure_ratAliases provided by Malpedia.
-
RE: https://infosec.exchange/@VirusBulletin/115660902138702248
How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
Here are some typical PureRAT indicators:
:windows: .NET malware
🔑 TLS version is 1.0
JA3fc54e0d16d9764783542f0146a98b300/07af4aa9e4d215a5ee63f9a0a277fbe3
JA4t10i070500_c50f5591e341_950472255fe9/t10i060500_4dc025c38c38_950472255fe9
JA3Sb74704234e6128f33bff9865696e31b3
📝 X.509 cert expires 9999-12-31 23:59:59 UTC
📡 C2 often runs on TCP 56001
All of them match on the sample analyzed in Trend's report -
RE: https://infosec.exchange/@VirusBulletin/115660902138702248
How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
Here are some typical PureRAT indicators:
:windows: .NET malware
🔑 TLS version is 1.0
JA3fc54e0d16d9764783542f0146a98b300/07af4aa9e4d215a5ee63f9a0a277fbe3
JA4t10i070500_c50f5591e341_950472255fe9/t10i060500_4dc025c38c38_950472255fe9
JA3Sb74704234e6128f33bff9865696e31b3
📝 X.509 cert expires 9999-12-31 23:59:59 UTC
📡 C2 often runs on TCP 56001
All of them match on the sample analyzed in Trend's report -
RE: https://infosec.exchange/@VirusBulletin/115660902138702248
How is this #ValleyRAT? It looks, swims and quacks like #PureRAT.
Here are some typical PureRAT indicators:
:windows: .NET malware
🔑 TLS version is 1.0
JA3fc54e0d16d9764783542f0146a98b300/07af4aa9e4d215a5ee63f9a0a277fbe3
JA4t10i070500_c50f5591e341_950472255fe9/t10i060500_4dc025c38c38_950472255fe9
JA3Sb74704234e6128f33bff9865696e31b3
📝 X.509 cert expires 9999-12-31 23:59:59 UTC
📡 C2 often runs on TCP 56001
All of them match on the sample analyzed in Trend's report -
Mentioned Malware Families: PseudoManuscrypt, ValleyRAT
Aliases for PseudoManuscrypt: win.pseudo_manuscrypt
Malpedia link for PseudoManuscrypt: https://malpedia.caad.fkie.fraunhofer.de/details/win.pseudo_manuscrypt
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_ratAliases provided by Malpedia.
-
Mentioned Malware Families: PseudoManuscrypt, ValleyRAT
Aliases for PseudoManuscrypt: win.pseudo_manuscrypt
Malpedia link for PseudoManuscrypt: https://malpedia.caad.fkie.fraunhofer.de/details/win.pseudo_manuscrypt
Aliases for ValleyRAT: win.valley_rat, Winos
Malpedia link for ValleyRAT: https://malpedia.caad.fkie.fraunhofer.de/details/win.valley_ratAliases provided by Malpedia.
-
ValleyRAT Campaign Targets Windows via WeChat and DingTalk https://gbhackers.com/valleyrat-campaign/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
ValleyRAT Campaign Targets Windows via WeChat and DingTalk https://gbhackers.com/valleyrat-campaign/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
ValleyRAT Campaign Targets Windows via WeChat and DingTalk https://gbhackers.com/valleyrat-campaign/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
Злоумышленники перенимают опыт коллег: что общего между SilverFox и APT41. Разбор атаки
Привет, Хабр! На связи Евгения Устинова, старший аналитик сетевой безопасности группы компаний «Гарда» . В статье хочу рассказать, как нам удалось связать инструментарий двух группировок через особенности реализации сетевых протоколов. Отследить эволюцию инструментов группировки SilverFox – например, ПО Winos – по отпечатку процедуры сетевой коммуникации оказалось довольно сложной задачей, поэтому я решила поделиться кейсом. Подключайтесь к расследованию
https://habr.com/ru/companies/garda/articles/962222/
#разбор_атаки #Winos #Silverfox #вредоносы #фишинг #ValleyRAT #apt41 #winnti
-
Злоумышленники перенимают опыт коллег: что общего между SilverFox и APT41. Разбор атаки
Привет, Хабр! На связи Евгения Устинова, старший аналитик сетевой безопасности группы компаний «Гарда» . В статье хочу рассказать, как нам удалось связать инструментарий двух группировок через особенности реализации сетевых протоколов. Отследить эволюцию инструментов группировки SilverFox – например, ПО Winos – по отпечатку процедуры сетевой коммуникации оказалось довольно сложной задачей, поэтому я решила поделиться кейсом. Подключайтесь к расследованию
https://habr.com/ru/companies/garda/articles/962222/
#разбор_атаки #Winos #Silverfox #вредоносы #фишинг #ValleyRAT #apt41 #winnti
-
Operation Silk Lure: Weaponizing Windows Scheduled Tasks for ValleyRAT Delivery https://gbhackers.com/operation-silk-lure/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
Operation Silk Lure: Weaponizing Windows Scheduled Tasks for ValleyRAT Delivery https://gbhackers.com/operation-silk-lure/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
Operation Silk Lure: Weaponizing Windows Scheduled Tasks for ValleyRAT Delivery https://gbhackers.com/operation-silk-lure/ #CyberSecurityNews #cybersecurity #ValleyRAT #Windows
-
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by #PseudoManuscrypt and #ValleyRAT.
https://netresec.com/?b=259a5af -
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by #PseudoManuscrypt and #ValleyRAT.
https://netresec.com/?b=259a5af -
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by #PseudoManuscrypt and #ValleyRAT.
https://netresec.com/?b=259a5af -
Chasing the Silver Fox: Cat & Mouse in Kernel Shadows
#SilverFox #ValleyRAT
https://research.checkpoint.com/2025/silver-fox-apt-vulnerable-drivers/