Fake Microsoft Teams Downloads Spread ValleyRAT Malware
ID: 822a72ab-9c9c-5b42-a2b5-49b8be23d34d
STIX ID: report--822a72ab-9c9c-5b42-a2b5-49b8be23d34d
Feed Name: GBHackers
The report details an active ValleyRAT distribution campaign using fraudulent Microsoft Teams download pages and trojanized ZIP installers that execute an NSIS installer to drop a loader, malicious DLL (utility.dll), and supporting binaries; it abuses legitimate GameBox.exe for DLL sideloading, modifies Defender exclusions, creates persistence via a service named CCGDAT, decrypts an AES payload in memory, and ultimately delivers an XOR-encrypted final payload from C2 for data theft (clipboard capture, keystrokes, continuous TCP C2). IOCs (file names and hashes) are provided and the activity is attributed to China-linked SilverFox APT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
