logo

ValleyRAT Malware Uses Stealthy Driver Install to Bypass Windows 11 Protections

ID: c48ff316-478e-5ea8-b7b5-326c70c0d51b

STIX ID: report--c48ff316-478e-5ea8-b7b5-326c70c0d51b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ValleyRAT (aka Winos/Winos4.0) is a sophisticated modular Windows remote-access trojan featuring a kernel-mode rootkit that can bypass protections on updated Windows 11 systems, plugin-based escalation and credential theft capabilities, and aggressive removal of security/EDR drivers; the public leak of the builder has increased accessibility to a broader range of threat actors and researchers observed a surge in samples over the past six months.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.