logo

Fake Microsoft Teams Downloads Spread ValleyRAT Malware

ID: 822a72ab-9c9c-5b42-a2b5-49b8be23d34d

STIX ID: report--822a72ab-9c9c-5b42-a2b5-49b8be23d34d

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Mayura Kathir

...
...

The report details an active ValleyRAT distribution campaign using fraudulent Microsoft Teams download pages and trojanized ZIP installers that execute an NSIS installer to drop a loader, malicious DLL (utility.dll), and supporting binaries; it abuses legitimate GameBox.exe for DLL sideloading, modifies Defender exclusions, creates persistence via a service named CCGDAT, decrypts an AES payload in memory, and ultimately delivers an XOR-encrypted final payload from C2 for data theft (clipboard capture, keystrokes, continuous TCP C2). IOCs (file names and hashes) are provided and the activity is attributed to China-linked SilverFox APT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.