logo

ValleyRAT Malware and the Evolving Landscape of Ransomware Threats 

ID: cdf56363-870f-5139-ba3d-55fb421158c7

STIX ID: report--cdf56363-870f-5139-ba3d-55fb421158c7

Feed Name: Morphisec Blog

Threat Score
75/100

Date Published: 2025-04-17

Date Updated: 2026-04-28

Author: Alon Shekalim

...
...

Morphisec researchers describe ValleyRAT, a sophisticated, memory-resident Remote Access Trojan attributed to the China-linked Silver Fox APT that targets high-value sectors. The report details multi-stage in-memory execution using DLL side-loading, process injection, and LOLBINs (e.g., nslookup.exe), notes expanded capabilities such as keylogging and registry persistence, provides IOCs (domains, filenames, hashes), and recommends preemptive defenses like Automated Moving Target Defense to mitigate detection-evasive attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.