ValleyRAT
Coverage of ValleyRAT in the Nexus archive.
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group Silver Fox targeted a Japanese industrial manufacturer using a 3-driver BYOVD chain to deliver ValleyRAT (Winos 4.0) for remote access. The campaign involved new vulnerable-driver abuse and exploitation of legitimate components.
- China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
A China-linked cybercrime group named TA4922 has expanded its phishing attacks to target organizations in the U.K., Germany, Italy, and South Africa. The group employs malware families such as ValleyRAT (Winos 4.0) and Atlas RAT (AtlasCross RAT) in its operations.
- Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
The China-backed advanced persistent threat group Silver Fox has launched tax-themed attacks on organizations in India and Russia, targeting various sectors with over 1,600 socially engineered messages to deliver malware. The attacks aim to deliver the previously undocumented ABCDoor backdoor, ValleyRAT, and other malware. This campaign highlights increased cyber threats from APT groups.