Legitimate Software Abused: Stealthy ValleyRAT Malware Campaign Targets Enterprise Users
ID: b7c94bce-3ae5-59e5-b9b8-1051d7a08188
STIX ID: report--b7c94bce-3ae5-59e5-b9b8-1051d7a08188
Feed Name: securityonline.info
A trojanized software campaign is distributing ValleyRAT disguised as Microsoft Teams installers via social platforms and lookalike download pages; the installers use NSIS and DLL sideloading through a Tencent executable (GameBox.exe) to deploy the RAT, disable Windows Defender via PowerShell exclusions, run encrypted in-memory shellcode (user.dat), capture keystrokes and clipboard data, and exfiltrate information — researchers link the operation to the SilverFox APT and provide an observable C2 IP (103.215.77.17).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
