logo

SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in Live ValleyRAT Campaign

ID: 106d273b-710f-5ee1-8671-09f22755da84

STIX ID: report--106d273b-710f-5ee1-8671-09f22755da84

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Tushar Subhra Dutta

...
...

The report details an active SilverFox campaign delivering a complex multi-stage RAT called ValleyRAT that uses DLL sideloading, repeated steganography, the Donut loader, and a Go-based RAT to deploy an AV-killer and a kernel rootkit; it targets corporate networks, steals cryptocurrency and Telegram data, persists via polymorphic builds and rotating file paths, and includes IoCs (SHA-256 hash and C2 domains) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.