China-Linked ValleyRAT Malware Resurfaces with Advanced Data Theft Tactics
ID: 61636020-240c-5536-848f-499e3f89a6c5
STIX ID: report--61636020-240c-5536-848f-499e3f89a6c5
Feed Name: The Hacker News
Threat Score
Security researchers uncovered an updated ValleyRAT campaign that uses an HFS-based downloader, multi-stage DLL sideloading, anti‑AV termination, and shellcode injection into svchost.exe to fetch and run the final ValleyRAT payload; separately, Fortinet reported a Spanish-targeted phishing chain delivering an updated Agent Tesla variant via Excel Add-In exploits (CVE-2017-0199/CVE-2017-11882) that loads PowerShell to retrieve the infostealer and keylogger.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
