Skip to content
Malware family Windows

ValleyRAT

ValleyRAT, also referred to as Winos 4.0 or WinOS 4.0 in overlapping reporting, is a multi-stage Windows remote access trojan associated in multiple investigations with the Silver Fox threat ecosystem and broader Gh0stRAT-derived tooling.

Profile source: Mallory opens in a new tab

ValleyRAT

Family profile

ValleyRAT, also referred to as Winos 4.0 or WinOS 4.0 in overlapping reporting, is a multi-stage Windows remote access trojan associated in multiple investigations with the Silver Fox threat ecosystem and broader Gh0stRAT-derived tooling. It has been active since at least 2023 and has been used in campaigns targeting Chinese- and Japanese-speaking users, Indian tax-related targets, and other victims through socially engineered delivery chains. Reported lures include tax-themed phishing, trojanized software installers, fake browser installers, and abuse of legitimate applications for DLL sideloading, including VLC-based chains. Some campaigns also used malicious disk images or compressed archives as intermediate stages.

Capabilities

  • Crypto Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
37 IP / 5 hostnames

Leading locations

  • HK37
  • US3
  • JP1

Leading providers

  • CTG Server Limited8
  • Alibaba (US) Technology Co., Ltd.6
  • Cloudie Limited5
  • Amazon.com, Inc.3
  • Tcloudnet3
  • AROSSCLOUD INC.2

Infrastructure traits

  • Hosting 37
  • Vpn 2
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

14 named in public reporting
TA428

Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.

SilverFox

The malware, tracked as ValleyRAT, is deployed by a hacking group known as SilverFox, and it stands out for one reason: it refuses to stop at just one payload.

Silver Fox

Seqrite said it identified infrastructure and tactical overlaps with Silver Fox, a Chinese cybercrime group previously attributed to tax-themed phishing campaigns that deliver ValleyRAT.

APT Silver Fox

The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.

APT41

The threat actor also attempted to use a downloader built using the advanced malicious framework Winos4.0. The downloader, placed under drivers\etc masquerading as hosts.exe, attempted to connect to the IP address 154.201.68[.]57. After a successful connection, it downloads the payload and saves it into the registry key d33f351a4aeea5e608853d1a56661059. It then executes the payload.

TA4922

Finally, this Proofpoint cybercrime analysis notes that the threat group continues to abuse the open-source Winos4.0 framework. In early 2026, researchers spotted a heavily modified variant featuring a massive codebase expansion.

SilverFox APT

Our investigation revealed that the delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant.

SwimSnake

Analysts found infrastructure overlaps between this campaign and previous npm typosquatting attacks that distributed ValleyRAT (also known as Winos 4.0).

APT-Q-27

SHA256 Family Relation 2cb5614936ef42e52c44ebb7b758bf57fde6c7b2d68cc21a7ec94d2f0adb3435 SilverFox / Winos4.0 Qt loader (yesterday's sample) Compiled 2026-04-08; lists Alibaba Cloud HK IPs including nodes in this cluster. | A published timeline showing the operator has been running on this namespace continuously since March 2025, and that yesterday's ValleyRAT ZPAQ sample (2cb56149…) is bound to this same infrastructure cluster.

CL-STA-0048

A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.

UTG-Q-1000

A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.

The Great Thief of Valley

The sample delivers ValleyRAT with a kernel-mode rootkit and employs a six-stage infection chain built around a legitimate zpaqfranz decompression binary used as a LOLBin, a ByteDance/TikTok elevation service binary used as a DLL sideloading host, and a vulnerable wnBios BIOS driver used via BYOVD for physical memory access.

Valley Thief

The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).

MuddyWater

Associated Analytic Story DarkSide Ransomware ... LockBit Ransomware ... Ransomware ... ValleyRAT

Exploited software

Vulnerabilities linked to ValleyRAT

1 CVEs

MITRE ATT&CK

ValleyRAT in ATT&CK

120 distinct techniques

Techniques

120 techniques
T1204.002 Malicious File T1036.005 Match Legitimate Resource Name or Location T1113 Screen Capture T1204.001 Malicious Link T1189 Drive-by Compromise T1105 Ingress Tool Transfer T1608.006 SEO Poisoning T1204 User Execution T1036 Masquerading T1106 Native API T1059.001 PowerShell T1140 Deobfuscate/Decode Files or Information T1562 Impair Defenses T1518.001 Security Software Discovery T1055 Process Injection T1070.004 File Deletion T1027.002 Software Packing T1548 Abuse Elevation Control Mechanism T1112 Modify Registry T1620 Reflective Code Loading T1027 Obfuscated Files or Information T1547.001 Registry Run Keys / Startup Folder T1566 Phishing T1528 Steal Application Access Token T1574 Hijack Execution Flow T1014 Rootkit T1574.001 DLL T1027.003 Steganography T1559.001 Component Object Model T1071 Application Layer Protocol T1115 Clipboard Data T1497 Virtualization/Sandbox Evasion T1027.013 Encrypted/Encoded File T1059.003 Windows Command Shell T1497.003 Time Based Checks T1055.003 Thread Execution Hijacking T1211 Exploitation for Defense Evasion T1566.002 Spearphishing Link T1497.001 System Checks T1055.012 Process Hollowing T1083 File and Directory Discovery T1012 Query Registry T1057 Process Discovery T1566.001 Spearphishing Attachment T1071.001 Web Protocols T1053.005 Scheduled Task T1082 System Information Discovery T1490 Inhibit System Recovery T1056.001 Keylogging T1055.002 Portable Executable Injection T1195.002 Compromise Software Supply Chain T1614 System Location Discovery T1095 Non-Application Layer Protocol T1059.005 Visual Basic T1572 Protocol Tunneling T1562.001 Disable or Modify Tools T1218.011 Rundll32 T1021.003 Distributed Component Object Model T1027.007 Dynamic API Resolution T1543.003 Windows Service T1562.009 Safe Mode Boot T1222.001 Windows File and Directory Permissions Modification T1566.003 Spearphishing via Service T1573 Encrypted Channel T1036.004 Masquerade Task or Service T1219 Remote Access Tools T1123 Audio Capture T1125 Video Capture T1090.003 Multi-hop Proxy T1070 Indicator Removal T1074 Data Staged T1070.006 Timestomp T1560 Archive Collected Data T1068 Exploitation for Privilege Escalation T1134.002 Create Process with Token T1195 Supply Chain Compromise T1218 System Binary Proxy Execution T1010 Application Window Discovery T1059.007 JavaScript T1583.001 Domains T1041 Exfiltration Over C2 Channel T1547.006 Kernel Modules and Extensions T1608.001 Upload Malware T1571 Non-Standard Port T1564.009 Resource Forking T1548.002 Bypass User Account Control T1129 Shared Modules T1104 Multi-Stage Channels T1120 Peripheral Device Discovery T1562.010 Downgrade Attack T1059 Command and Scripting Interpreter T1016 System Network Configuration Discovery T1564.001 Hidden Files and Directories T1622 Debugger Evasion T1583.004 Server T1197 BITS Jobs T1583.003 Virtual Private Server T1573.001 Symmetric Cryptography T1614.001 System Language Discovery T1134.001 Token Impersonation/Theft T1007 System Service Discovery T1547 Boot or Logon Autostart Execution T1090 Proxy T1218.007 Msiexec T1008 Fallback Channels T1568.002 Domain Generation Algorithms T1584.004 Server T1555 Credentials from Password Stores T1056 Input Capture T1005 Data from Local System T1598 Phishing for Information T1480.002 Mutual Exclusion T1027.005 Indicator Removal from Tools T1218.010 Regsvr32 T1593 Search Open Websites/Domains T1584.001 Domains T1102 Web Service T1592 Gather Victim Host Information T1053 Scheduled Task/Job T1546 Event Triggered Execution

Reporting

Research mentioning ValleyRAT

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Winos 4.03

Jul 10
Codeby

SEO-poisoning атаки: kill chain, IOC и детект в SIEM

Установка бэкдоров - RAT для долгосрочного контроля (Winos4.0, SectopRAT, Oyster) ... вредоносное ПО семейства Winos4.0. ... Winos4.0 давал полный контроль: скриншоты, сбор системной информации, управление файлами, выполнение произвольного кода по команде C2.

Jul 7
Gurucul Threat Research

China-Nexus APT Targets India With Fake Tax Assessment Campaign Using DLL Hijacking | Community Portal | Gurucul

Researchers identified a social engineering campaign impersonating the Indian Income Tax Department to deliver the ValleyRat Remote Access Trojan (RAT) through a multi-stage infection chain involving a malicious VHDX, DLL SideLoading, and encrypted in-memory payload execution.

Jul 6
Cyber Security News

SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in Live ValleyRAT Campaign

The malware, tracked as ValleyRAT, is deployed by a hacking group known as SilverFox, and it stands out for one reason: it refuses to stop at just one payload.

Jul 6
The Hacker News

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Seqrite said it identified infrastructure and tactical overlaps with Silver Fox, a Chinese cybercrime group previously attributed to tax-themed phishing campaigns that deliver ValleyRAT.

Jul 2
Cyber Security News

Hackers Use Fake VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT

Researchers have uncovered a campaign that abuses the popular VLC media player to quietly install ValleyRAT, a remote access trojan that gives attackers full control over infected computers.

Jul 2
Cyber Security News

Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT - Cyber Security News

Researchers have uncovered a campaign that abuses the popular VLC media player to quietly install ValleyRAT, a remote access trojan that gives attackers full control over infected computers.

Jun 30
Levelblue Spiderlabs

An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

The malware ValleyRAT, which is the focus of this report, has been repeatedly observed in the wild since it was first named by Proofpoint in 2023. As its name suggests, ValleyRAT is a Remote Access Trojan (RAT) that enables threat actors to remotely control compromised systems.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.