logo

Fake Installer: Ultimately, ValleyRAT infection

ID: a313cd8a-498c-55de-b9ad-808f55a4deea

STIX ID: report--a313cd8a-498c-55de-b9ad-808f55a4deea

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason GSOC analyzed a sophisticated fake LINE installer (SHA1 b02a99344f2fa81636ad913f805b52051debe529) that uses NSIS packaging, code signing (with a suspicious certificate), PowerShell and Task Scheduler manipulations, and advanced injection (PoolParty Variant 7) to load shellcode, evade detection, and download additional payloads (likely ValleyRat); the report provides detailed IOCs, behavior analysis, detection rules, and notes similarities to prior samples and potential APT links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.