logo

ValleyRAT Mimic as LINE Installer Attacking Users to Steal Login Details

ID: 6c46a9bd-4d6c-5db4-bd7d-2537c8b6bfc1

STIX ID: report--6c46a9bd-4d6c-5db4-bd7d-2537c8b6bfc1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**A sophisticated ValleyRAT campaign masquerading as a LINE installer targets Chinese-speaking users, using multi-stage shellcode loading, PoolParty Variant 7 process injection into Explorer.exe and UserAccountBroker.exe, Windows Defender disabling via PowerShell, deployment of a malicious intel.dll performing sandbox checks, scheduled-task persistence, and credential theft while communicating with C2 servers.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.