securityonline.info 8/31/2026, 11:28:38 AM · external

ValleyRAT backdoor hides in fake signed installers targeting Asia

ValleyRAT backdoor hides in fake signed installers targeting Asia
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor

THE ValleyRAT campaign, attributed to the Silver Fox group, targets users in China and India, delivering a backdoor through signed adware packages disguised as legitimate software. Kaspersky researchers reported over 100,000 detections affecting more than 1,500 unique users. The malicious installer mimics popular applications and uses DLL sideloading to execute a backdoor, which captures keystrokes, steals clipboard data, and can execute commands remotely. To mitigate risk, organizations should enforce application allowlisting, monitor registry changes, and prevent users from disabling antivirus tools.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline