THE ValleyRAT campaign, attributed to the Silver Fox group, targets users in China and India, delivering a backdoor through signed adware packages disguised as legitimate software. Kaspersky researchers reported over 100,000 detections affecting more than 1,500 unique users. The malicious installer mimics popular applications and uses DLL sideloading to execute a backdoor, which captures keystrokes, steals clipboard data, and can execute commands remotely. To mitigate risk, organizations should enforce application allowlisting, monitor registry changes, and prevent users from disabling antivirus tools.
ValleyRAT backdoor hides in fake signed installers targeting Asia
CyberSIXT Evidence Panel
Primary Source
securelist.com
Threat Actor
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
ValleyRAT backdoor hides in fake signed installers targeting Asia
securityonline.info
-
ValleyRAT backdoor hides in adware, uses DLL sideloading to spy
securelist.com