SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in Live ValleyRAT Campaign
ID: 106d273b-710f-5ee1-8671-09f22755da84
STIX ID: report--106d273b-710f-5ee1-8671-09f22755da84
Feed Name: cybersecurityNews.com
Threat Score
The report details an active SilverFox campaign delivering a complex multi-stage RAT called ValleyRAT that uses DLL sideloading, repeated steganography, the Donut loader, and a Go-based RAT to deploy an AV-killer and a kernel rootkit; it targets corporate networks, steals cryptocurrency and Telegram data, persists via polymorphic builds and rotating file paths, and includes IoCs (SHA-256 hash and C2 domains) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
