ValleyRAT Malware and the Evolving Landscape of Ransomware Threats
ID: cdf56363-870f-5139-ba3d-55fb421158c7
STIX ID: report--cdf56363-870f-5139-ba3d-55fb421158c7
Feed Name: Morphisec Blog
Morphisec researchers describe ValleyRAT, a sophisticated, memory-resident Remote Access Trojan attributed to the China-linked Silver Fox APT that targets high-value sectors. The report details multi-stage in-memory execution using DLL side-loading, process injection, and LOLBINs (e.g., nslookup.exe), notes expanded capabilities such as keylogging and registry persistence, provides IOCs (domains, filenames, hashes), and recommends preemptive defenses like Automated Moving Target Defense to mitigate detection-evasive attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
