Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 61 IP / 17 hostnames
ValleyRAT, also known as Winos 4.0, is a modular Windows backdoor with remote-control, surveillance, reconnaissance, and payload-delivery capabilities.
Profile source: Mallory opens in a new tabValleyRAT
ValleyRAT, also known as Winos 4.0, is a modular Windows backdoor with remote-control, surveillance, reconnaissance, and payload-delivery capabilities. It collects host details, active-window information, keystrokes, clipboard contents, and screenshots, and can exfiltrate collected keylogging and clipboard data. Operators can issue commands to reboot or shut down the host, clear logs, update command-and-control configuration, and retrieve additional DLL or shellcode modules. Downloaded shellcode may be executed through process hollowing, and the malware can inject into a Windows process to recover execution after termination.
ValleyRAT uses defense-evasion and resilience features including encrypted in-memory payload loading, security- and traffic-analysis tool discovery, critical-process protection that can crash the host if forcibly terminated, and configuration obfuscation. Observed delivery chains have trojanized the legitimate QN Wallpaper application, abusing DLL sideloading through signed executables to load an encrypted ValleyRAT payload in memory. Associated installers establish autorun persistence, attempt to disable Microsoft Defender, and may seek elevated privileges.
ValleyRAT has been observed in campaigns affecting users primarily in China and India, as well as phishing activity targeting organizations in Japan and Indian taxpayers. Activity involving the QN Wallpaper delivery chain has been assessed as likely linked to the China-nexus Silver Fox threat actor, although ValleyRAT attribution is not exclusive because the family has been used by multiple actors.
C2 tracking
Derp observations, rolling seven-day window
Samples
0fdb63034c7c655e05b3a7725d5e2776606c323ae534bf6f30cd9eeadb3a879d 5ee63b6078992c5f40854440348de809ca62b94dbe5198fec1db2b541b6c4ac5 4ba01b04681a5273facdd8b17e7b7b2246ee0eab6168c932946e7e96b9099e2d 765d34b234970be7eb12351051eff45d5d9cab515da07e4615381eacdc672d3b 86b34bd9245e406c15c88d0b5b8b11ae34f52bf1c16a1e0a0bfe80780efbda8c a2a4be3a4b8c9738d92ff0dfa13886e2a629f9f820e2169ed33c883dc548ce4b da169efdf43f4f2e87937efaaaf328dd659e28740411d1904a5bd0908ea5e061 2a757c865724e3b6543c66281ebb0dca5cb7e0a300d38bfd7559e5ab5d04f7d4 3fb86b9f8d2751a061ad6afb9e9e28362d67473d60214ebf82a3c3806ced0f55 41d9c8f7662e76d62da7aac907d6419be76f60259241e16e7d8025ed4aa34d12 Reported operators
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
The threat actor also attempted to use a downloader built using the advanced malicious framework Winos4.0. The downloader, placed under drivers\etc masquerading as hosts.exe, attempted to connect to the IP address 154.201.68[.]57. After a successful connection, it downloads the payload and saves it into the registry key d33f351a4aeea5e608853d1a56661059. It then executes the payload.
Analysts found infrastructure overlaps between this campaign and previous npm typosquatting attacks that distributed ValleyRAT (also known as Winos 4.0).
SHA256 Family Relation 2cb5614936ef42e52c44ebb7b758bf57fde6c7b2d68cc21a7ec94d2f0adb3435 SilverFox / Winos4.0 Qt loader (yesterday's sample) Compiled 2026-04-08; lists Alibaba Cloud HK IPs including nodes in this cluster. | A published timeline showing the operator has been running on this namespace continuously since March 2025, and that yesterday's ValleyRAT ZPAQ sample (2cb56149…) is bound to this same infrastructure cluster.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
The sample delivers ValleyRAT with a kernel-mode rootkit and employs a six-stage infection chain built around a legitimate zpaqfranz decompression binary used as a LOLBin, a ByteDance/TikTok elevation service binary used as a DLL sideloading host, and a vulnerable wnBios BIOS driver used via BYOVD for physical memory access.
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
Associated Analytic Story DarkSide Ransomware ... LockBit Ransomware ... Ransomware ... ValleyRAT
Exploited software
MITRE ATT&CK
Reporting
A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.
Threat actors in multiple intrusions abused Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint protections from kernel mode after gaining access through phishing or compromised remote-access credentials. Huntress reported an intrusion that began with stolen SonicWall SSLVPN credentials and escalated into deployment of an EDR killer built around a legitimate EnCase forensic driver, which Windows loaded despite the driver’s expired and revoked certificate. The malware hid the embedded driver with a 256-word substitution scheme, installed it as a kernel service with OEM-like naming, and repeatedly terminated a hashed list of 59 security processes before responders disrupted the attack ahead of ransomware deployment. Separate research tied similar tradecraft to SilverFox, which used vulnerable or signed drivers including BootRepair.sys, EnPortv.sys, wsftprm.sys, and a Microsoft-signed WatchDog Antimalware driver derived from the Zemana SDK to kill protected security processes and deliver ValleyRAT/Winos. Cato documented a campaign against a Japanese industrial manufacturer that used invoice-themed phishing, abused QQ and Tencent Cloud for delivery, and sideloaded a malicious PDFCORE8.dll through legitimate ConvertToPDF.exe and PDFDirect.exe; Check Point found SilverFox also adapted quickly to blocklists by modifying a single byte in an unauthenticated Authenticode timestamp area, preserving a valid Microsoft signature while changing the file hash. The combined reporting shows attackers increasingly pairing initial access with signed-driver abuse, DLL sideloading, and stealthy loaders to neutralize EDR before establishing persistent remote access.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.