logo

ValleyRAT_S2: Stealth Intrusions Aimed at Financial Data Exfiltration

ID: f070a7eb-03f5-597a-adfa-4c07dff53ee6

STIX ID: report--f070a7eb-03f5-597a-adfa-4c07dff53ee6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ValleyRAT_S2 is a modular, C++ second-stage Remote Access Trojan active across Chinese-speaking regions and Southeast Asia, delivered via DLL side-loading, fake "AI" tools, cracked software, and targeted phishing; it performs extensive system reconnaissance, establishes persistence (Task Scheduler, Volume Shadow Copy), uses process injection and DLL masquerading for evasion, logs keystrokes, and exfiltrates data to hardcoded C2 servers (e.g., 27.124.3.175:14852).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.