logo

Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits

ID: 597bafe6-b6d8-5d55-8872-5ece5e3658ba

STIX ID: report--597bafe6-b6d8-5d55-8872-5ece5e3658ba

Feed Name: Check Point Research

Threat Score
85/100

Date Published: 2025-12-10

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research dissects the ValleyRAT (Winos) modular backdoor and its embedded 64-bit kernel rootkit, using leaked builder and development artifacts to reverse engineer 19 main plugins and the driver. The report details stealthy driver installation (including a MalSeclogon-based stealth mode), APC-based user-mode shellcode injection, a kernel ForceDeleteFile routine targeting many AV/EDR drivers, compilation and signing artefacts, IOCs (file hashes), and in-the-wild detection statistics showing ~6,000 related samples with a recent surge after the builder leak.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.