Fake Installer: Ultimately, ValleyRAT infection
ID: a313cd8a-498c-55de-b9ad-808f55a4deea
STIX ID: report--a313cd8a-498c-55de-b9ad-808f55a4deea
Feed Name: Cybereason Blog
Cybereason GSOC analyzed a sophisticated fake LINE installer (SHA1 b02a99344f2fa81636ad913f805b52051debe529) that uses NSIS packaging, code signing (with a suspicious certificate), PowerShell and Task Scheduler manipulations, and advanced injection (PoolParty Variant 7) to load shellcode, evade detection, and download additional payloads (likely ValleyRat); the report provides detailed IOCs, behavior analysis, detection rules, and notes similarities to prior samples and potential APT links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
