Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India
ID: 2ea7b93a-dbc3-5f6a-b064-df1008c7fda1
STIX ID: report--2ea7b93a-dbc3-5f6a-b064-df1008c7fda1
Feed Name: cybersecurityNews.com
Securelist researchers observed a campaign that uses seemingly harmless adware installers to deploy a tampered QN Wallpaper application which DLL-sideloads a malicious libcef.dll to launch the ValleyRAT backdoor; the malware performs surveillance (keystrokes, screenshots, clipboard), persistence (startup entries, process injection, marking processes critical), attempts to disable Microsoft Defender, and communicates with listed C2 endpoints — over 100,000 detections and ~1,500 unique users were reported, mainly in China and India, with IoCs provided for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
