logo

Operation Silk Lure: Chinese Espionage Targets FinTech with Malicious Resume LNK to Implant ValleyRAT

ID: 0ed4707e-471f-5c78-8613-c1d149fbb374

STIX ID: report--0ed4707e-471f-5c78-8613-c1d149fbb374

Feed Name: securityonline.info

Threat Score
82/100

Date Published: 2025-10-17

Date Updated: 2026-04-22

Author: Ddos

...
...

Seqrite Labs uncovered 'Operation Silk Lure', a targeted espionage campaign against Chinese FinTech and cryptocurrency firms that uses localized, malicious resume .LNK files to drop a PowerShell-based downloader which retrieves keytool.exe and jli.dll; the loader decrypts RC4-protected shellcode (RC4 key '123cba') exposing C2 206.119.175.16 and installs an evolved ValleyRAT backdoor that performs fingerprinting, keylogging, plugin delivery, anti-AV actions, and daily persistence via a scheduled task named 'Security'.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.