Cybercriminals Abuse Microsoft Teams Brand To Spread ValleyRAT
ID: c3ad0d36-db0e-5c2d-a623-9221b7c5f0fd
STIX ID: report--c3ad0d36-db0e-5c2d-a623-9221b7c5f0fd
Feed Name: Cyber Press
The report describes a sophisticated, active campaign that uses fake Microsoft Teams download pages to deliver ValleyRAT. The installer drops a trojanized payload and a legitimate Teams installer to avoid suspicion, performs DLL sideloading (using GameBox.exe to load Utility.dll), disables Windows Defender exclusions via PowerShell, decrypts payloads in-memory, resolves APIs via hashing, and contacts C2 to fetch an XOR-encrypted ValleyRAT module that steals clipboard data. The write-up includes attribution to a China-linked APT (SilverFox) and provides file-based IoCs (file names and MD5 hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
