logo

New Updates to ValleyRAT

ID: 59f130b6-50bd-5894-9d2f-3fab62927993

STIX ID: report--59f130b6-50bd-5894-9d2f-3fab62927993

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-05-27

Date Updated: 2026-05-01

...
...

This technical report analyzes a multipart attack chain delivering ValleyRAT: an initial downloader retrieves and decrypts staged files, a malicious wwlib.dll sideloaded by WINWORD2013.EXE loads and injects shellcode into svchost.exe, which then fetches and reflectively loads a final DLL payload. The analysis documents decryption keys and algorithms, dynamic API resolution, C2 configuration and formats (including example IPs/ports), persistence and anti-AV checks, device fingerprinting and bot ID generation, and newly observed RAT commands and capabilities, attributing the campaign to the actor known as The Great Thief of Valley (Silver Fox).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.