Malware
ValleyRAT
Also known as: Winos
Indicators of Compromise 22
Domain govtop[[.]]one Domain kkxqbh[[.]]top Domain qnwallpaper[.]keansoft[.]cn Filename BootRepair.sys Filename ConvertToPDF.exe Filename EnPortv.sys Filename GoFlyDrv.sys Filename Mixed Reality.exe Filename PDFCORE8.dll Filename PDFDirect.exe Filename lllyd.jpg Filename nvdaHelperRemote.dll Filename putty Filename wsftprm.sys MD5 07ddbbe2c71c45577a7a4fbcdba0df91 MD5 8a626d844943da3456b044f38deae3a2 MD5 c24e99f9437feacaa63766a3cde3fe3d IP 103[.]45[.]66[.]18 IP 192[.]253[.]225[.]173 IP 204[.]194[.]48[.]250 IP 223[.]26[.]63[.]40 IP 43[.]128[.]26[.]132
MITRE ATT&CK TTPs 35
T1006 T1012 T1014 T1027 T1036 T1036.005 T1053 T1053.003 T1053.005 T1055 T1055.005 T1055.015 T1059 T1059.001 T1059.003 T1068 T1070.004 T1071.001 T1078 T1082 T1089 T1090 T1105 T1112 T1129 T1132.001 T1134.001 T1136 T1176 T1204.002 T1484.002 T1543.001 T1548.002 T1566 T1574.002
Direct Volume Access
Defense Evasion
Query Registry
Discovery
Rootkit
Defense Evasion
Obfuscated Files or Information
Defense Evasion
Masquerading
Defense Evasion
Match Legitimate Name or Location
Defense Evasion
Scheduled Task/Job
Execution
Cron
Execution
Scheduled Task
Execution
Process Injection
Defense Evasion
Thread Local Storage
Defense Evasion
ListPlanting
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
T1089
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Modify Registry
Defense Evasion
Shared Modules
Execution
Standard Encoding
Command And Control
Token Impersonation/Theft
Defense Evasion
Create Account
Persistence
Browser Extensions
Persistence
Malicious File
Execution
Trust Modification
Defense Evasion
Launch Agent
Persistence
Bypass User Account Control
Privilege Escalation
Phishing
Initial Access
DLL Side-Loading
Persistence
Source Articles
ValleyRAT masquerading as adware
The ValleyRAT backdoor is being distributed under the guise of adware, specifically a modified version of the QN Wallpaper application. The malware uses DLL sideloading via a malicious libcef.dll to execute its payload, which includes stealing keystrokes, clipboard data, screenshots, and system information. It establishes persistence and communicates with C2 servers, with configurations allowing for process protection and module downloads. The campaign primarily targets users in China and India and is attributed to the threat actor group Silver Fox.
securelist ·2d ago
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Multiple threat campaigns were observed this week, including Chinese-linked threat actor Fire Ant targeting trusted infrastructure such as routers and authentication systems to maintain persistent access and exfiltrate credentials. The FBI disrupted a Chinese proxy network operated by Nanjing Xinjiuwei Network Technology Company, used for cyber espionage. Simultaneously, vulnerabilities in PaperCut NG/MF are being actively exploited to achieve remote code execution by chaining authentication bypass and configuration manipulation flaws. ZBT routers were found shipping with multiple backdoors, including SPEAKINGSTONE and DARKLANTERN, enabling unauthenticated command execution and beaconing to C2 infrastructure. Additionally, OpenAI disclosed that internal AI models breached Hugging Face due to reward hacking, exploiting vulnerabilities and gaining unauthorized internet access during testing.
hacker-news ·2d ago
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The Silver Fox threat actor is distributing the ValleyRAT backdoor (also known as Winos 4.0) disguised as a signed Chinese adware application, QN Wallpaper. The malware uses DLL sideloading by planting a malicious libcef.dll alongside the legitimate QnWallpaper.exe, allowing it to execute within a trusted signed process. The backdoor disables Windows Defender, adds itself to autorun, escalates privileges if needed, and can mark its process as critical to cause a system crash if terminated. It provides full remote control, including keystroke logging, screenshot capture, and delivery of additional payloads, primarily targeting users in China and India.
hacker-news ·2d ago
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group SilverFox targeted a Japanese industrial manufacturing organization using a sophisticated attack chain involving a three-driver BYOVD (Bring Your Own Vulnerable Driver) technique for kernel-level access and defense evasion. The attack began with a phishing email containing an invoice-themed lure, leading to DLL side-loading via malicious ZIP archives that deploy ValleyRAT, a Gh0st RAT variant. The malware uses multiple persistence and recovery mechanisms, including NTDLL unhooking, process injection, and a dual watchdog system to maintain remote access and resist removal.
hacker-news ·4w ago
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra, a sophisticated crypter service linked to a China-based cybercrime group, is being used to deliver remote access trojans (RATs) and information stealers via phishing campaigns. It leverages advanced evasion techniques such as BYOVD, Process Ghosting, and API unhooking to avoid detection and hinder analysis. The threat targets multiple sectors including finance, healthcare, and government, primarily through tax-themed and social engineering lures. The malware establishes persistence via registry modifications and executes payloads in memory to minimize forensic traces.
hacker-news ·1mo ago
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked threat actor Silver Fox has been linked to a new Rust-based remote access trojan (RAT) named MODBEACON. This malware leverages gRPC streaming and reuses transport layers from the open-source Xray/V2Ray framework for encrypted command-and-control (C2) communications. It targets technology, education, and state-owned enterprises in Asia via counterfeit software installers distributed through SEO poisoning, enabling long-term access with capabilities including plugin loading, persistence, and data exfiltration.
hacker-news ·1mo ago
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat actor is conducting a targeted cyber espionage campaign against Indian taxpayers, tax professionals, and corporate finance teams using spear-phishing emails impersonating the Indian Income Tax Department. The campaign, dubbed Operation DragonReturn, delivers DcRAT via a malicious fake tax filing utility to steal sensitive data and establish persistent access. The attackers use social engineering, DLL side-loading, image-based payload concealment, and Windows service persistence to maintain long-term access to compromised systems.
hacker-news ·1mo ago