#ValleyRAT
「税務書類のご確認のお願い」というメールにご注意くださいとのこと。

税務調査を装うメールを用いたValleyRATへの感染攻撃に関する注意喚起 – wizSafe Security Signal -安心・安全への道標- IIJ wizsafe.iij.ad.jp/2026/01/2099/
税務調査を装うメールを用いたValleyRATへの感染攻撃に関する注意喚起
wizsafe.iij.ad.jp
January 24, 2026 at 7:18 AM
Watch out as this new ValleyRAT malware variant is spreading via fake downloads, including Chrome, TikTok, and even a fake telecom site!

Read: hackread.com/valleyrat-ma...

#CyberSecurity #Malware #ValleyRAT #SilverFox
New ValleyRAT Malware Variant Spreading via Fake Chrome Downloads
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
February 4, 2025 at 4:53 PM
⚠️ The #SilverFox APT is exploiting a Microsoft‑signed but vulnerable driver to disable Windows security on Win 10/11 and install #ValleyRAT malware.

Details: hackread.com/silver-fox-a...

#CyberSecurity #Malware #China #InfoSec #Windows
Silver Fox APT Exploits Signed Windows Driver to Deliver ValleyRAT
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 2, 2025 at 9:38 AM
Love hacker news. Edumaction and awareness is imperative thehackernews.com/2025/12/silv...
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
Silver Fox targets China with a fake Teams installer that delivers ValleyRAT malware through an SEO poisoning attack.
thehackernews.com
December 4, 2025 at 8:16 PM
ValleyRAT Attacking Org’s Accounting Department With New Delivery Techniques
ValleyRAT Attacking Org's Accounting Department With New Delivery Techniques
cybersecuritynews.com
February 4, 2025 at 6:49 AM
-> 39140128092026.824.img -> pdfcorE8.dll, 他正規ファイルの悪用
www.virustotal.com/gui/file/952...
tria.ge/260928-g9w2n...
app.any.run/tasks/6d2ffd...
マルウェア #ValleyRAT
■C2
45.202.1[.]249:913
45.202.1[.]249:912

引用元:
x.com/harugasumi/s...
September 28, 2026 at 7:24 AM
Malware Warning: Silver Fox is distributing ValleyRAT in China with a fake Microsoft Teams installer using SEO poisoning to trick users into malware downloads. Protect systems by avoiding unverified download sites!
📌 sctocs.com/silver-fox-v...
Silver Fox Distributes ValleyRAT In China Through Fake Microsoft Teams Installer - SCtoCS
Silver Fox is spreading ValleyRAT malware in China by using a fake Microsoft Teams installer that tricks users into downloading malicious files.
sctocs.com
December 5, 2025 at 7:39 PM
PNGPlug loader uses fake MSI installers to spread ValleyRAT (Silver Fox/Void Arachne) malware in Chinese-speaking areas. It uses PNG files for persistence and a DLL for injection. ValleyRAT provides remote access.#PNGPlugValleyRAT
January 21, 2025 at 7:04 AM
Gh0stKCP is a C2 transport protocol based on KCP. It has been used by malware families such as #PseudoManuscrypt and #ValleyRAT.
netresec.com?b=259a5af
Gh0stKCP Protocol
Gh0stKCP is a command-and-control (C2) transport protocol based on KCP. It has been used by malware families such as PseudoManuscrypt and ValleyRAT/Winos4.0. @Jane_0sint recently tweeted about ValleyR...
netresec.com
September 24, 2025 at 12:22 PM
マルウェアValleyRAT、認証情報を盗むことを目的にLINEインストーラーを装って配布
#CybersecurityNews
www.ithome.com.tw/news/173803
惡意軟體ValleyRAT假借LINE安裝程式散布,目的是竊取憑證
資安公司Cybereason指出,他們看到數起中國駭客駭客佯稱提供LINE安裝程式的攻擊行動,最終目的是散布ValleyRAT(Winos 4.0),呼籲使用者要提高警覺,企業也要根據相關特徵來防堵駭客的活動
www.ithome.com.tw
February 12, 2026 at 8:20 AM
PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
January 21, 2025 at 7:07 AM
Beware of fake Chrome sites distributing ValleyRAT malware targeting Chinese-speaking users in finance and sales. Always download software from official sources to protect against #cybersecurity threats. Stay informed and safe online! #malware #threat
Fake Chrome Sites Distribute ValleyRAT Malware to Users
Bogus websites posing as Google Chrome installers have been found to distribute the ValleyRAT trojan, primarily targeting Chinese-speaking users in key financial and sales roles.
decrypt.lol
February 7, 2025 at 11:49 AM
-Five Eyes releases guide on securing edge devices
-SmokeLoader abuses 7-Zip zero-day
-Malware reports on ValleyRAT, FleshStealer, FlexibleFerret, Sshdinjector
-AMD Zen vulnerability impacts the cloud
-Unpatched Sysinternals vulns
-Supply chain attack via S3 buckets
-BSides London and Belfast videos
February 5, 2025 at 10:44 AM
Pivoting on hashes and IPs ➡️ Ping32 RMM and ValleyRAT
👾 d43fdaa1f0ee09d7e5f0f94ee9df7b6c
📡 143.92.37.168:18987 (UDP)
👾 8266b00c4e45d728cef78b3f5a865f68
📡 143.92.37.168:10086 (UDP)
netresec.com?b=2666e31
Ping32 RMM and ValleyRAT
Fareed Radzi recently blogged about a malware campaign observed earlier in June by Kasperskys GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through What...
netresec.com
June 25, 2026 at 10:15 AM
■ダウンロード
PDF_資金移動完了証明書.ZIP -> hdp.dll, PDF_資金移動完了証明書.exe, 他.txtファイル
www.virustotal.com/gui/file/4df...
tria.ge/260925-mzjw8...
app.any.run/tasks/be21fb...
マルウェア #ValleyRAT
■通信先
hxxp[:]//apm.hexin[.]cn/trace?appId=4&isZip=0
(58.220.49[.]156:80)
■C2
103.42.30[.]245:7811
103.42.30[.]245:7800
September 25, 2026 at 12:31 PM
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
SilverFox targeted a Japanese manufacturer using new DLL sideloading methods, kernel drivers, and enhanced ValleyRAT persistence.
securityaffairs.com
July 31, 2026 at 7:41 AM
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
thehackernews.com
February 6, 2025 at 3:36 PM
ValleyRAT Malware Attack Windows Systems Using Weaponised Microsoft Office Doc
ValleyRAT Malware Attack Windows Systems Using Weaponised Microsoft Office Doc
A sophisticated cyberattack targeting Chinese-speaking users is spreading multi-stage malware known as ValleyRAT.
cybersecuritynews.com
August 26, 2024 at 2:31 PM
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking thehackernews.com/2025/02/fake...
Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
Fake Chrome sites spread ValleyRAT via DLL hijacking, targeting finance and sales with keylogging and remote execution.
thehackernews.com
February 9, 2025 at 2:41 PM
Urgent: ValleyRAT malware targets Chrome users (finance/accounting). Drive-by downloads via phishing & fake sites exploit multiple critical Chrome vulnerabilities (CVE-2025-0444, etc.). Update Chrome & use official sources only.#ValleyRATAlert
February 9, 2025 at 8:23 PM
Silver Fox's ValleyRAT malware, spread via fake Chrome installers, targets Chinese financial firms. It uses DLL hijacking and a Douyin executable for payload injection, stealing keystrokes and screen data.#SilverFoxValleyRAT
February 6, 2025 at 4:06 PM