An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails
ID: af6186c2-543a-5f0d-9d2f-9ca82ff42238
STIX ID: report--af6186c2-543a-5f0d-9d2f-9ca82ff42238
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
LevelBlue’s GSOC report analyzes ValleyRAT activity observed since 2025, documenting two primary attack vectors (fake installers and malicious emails), describing a detailed malicious-email campaign that uses ZIP-delivered EXE+DLL sideloading, fileless RC4-encrypted payloads executed via Donut-generated shellcode and process injection, multiple anti-analysis checks, detection logic, IOCs, and recommended prevention/remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
