logo

Cybercriminals Abuse Microsoft Teams Brand To Spread ValleyRAT

ID: c3ad0d36-db0e-5c2d-a623-9221b7c5f0fd

STIX ID: report--c3ad0d36-db0e-5c2d-a623-9221b7c5f0fd

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Varshini

...
...

The report describes a sophisticated, active campaign that uses fake Microsoft Teams download pages to deliver ValleyRAT. The installer drops a trojanized payload and a legitimate Teams installer to avoid suspicion, performs DLL sideloading (using GameBox.exe to load Utility.dll), disables Windows Defender exclusions via PowerShell, decrypts payloads in-memory, resolves APIs via hashing, and contacts C2 to fetch an XOR-encrypted ValleyRAT module that steals clipboard data. The write-up includes attribution to a China-linked APT (SilverFox) and provides file-based IoCs (file names and MD5 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.