logo

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

ID: af6186c2-543a-5f0d-9d2f-9ca82ff42238

STIX ID: report--af6186c2-543a-5f0d-9d2f-9ca82ff42238

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
72/100

Date Published: 2026-06-30

Date Updated: 2026-07-02

Author: Hajime Takai

...
...

LevelBlue’s GSOC report analyzes ValleyRAT activity observed since 2025, documenting two primary attack vectors (fake installers and malicious emails), describing a detailed malicious-email campaign that uses ZIP-delivered EXE+DLL sideloading, fileless RC4-encrypted payloads executed via Donut-generated shellcode and process injection, multiple anti-analysis checks, detection logic, IOCs, and recommended prevention/remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.