logo

Hackers Use Fake VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT

ID: a9355b0e-101d-5965-af8a-0d5ecb995141

STIX ID: report--a9355b0e-101d-5965-af8a-0d5ecb995141

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Tushar Subhra Dutta

...
...

This report details a phishing-driven campaign that leverages a genuine VLC executable paired with a malicious libvlc.dll to sideload and deploy ValleyRAT. The operators use ZIP-based lures targeting Chinese and Japanese users, RC4-encrypted in-memory payloads with process injection (fileless execution), sandbox-avoidance checks, and persistence via registry autorun; the write-up includes multiple indicators of compromise (hashes, domain, URL) and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.