New Updates to ValleyRAT
ID: 59f130b6-50bd-5894-9d2f-3fab62927993
STIX ID: report--59f130b6-50bd-5894-9d2f-3fab62927993
Feed Name: Zscaler Security Research Blog
This technical report analyzes a multipart attack chain delivering ValleyRAT: an initial downloader retrieves and decrypts staged files, a malicious wwlib.dll sideloaded by WINWORD2013.EXE loads and injects shellcode into svchost.exe, which then fetches and reflectively loads a final DLL payload. The analysis documents decryption keys and algorithms, dynamic API resolution, C2 configuration and formats (including example IPs/ports), persistence and anti-AV checks, device fingerprinting and bot ID generation, and newly observed RAT commands and capabilities, attributing the campaign to the actor known as The Great Thief of Valley (Silver Fox).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
