Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 37 IP / 5 hostnames
ValleyRAT, also referred to as Winos 4.0 or WinOS 4.0 in overlapping reporting, is a multi-stage Windows remote access trojan associated in multiple investigations with the Silver Fox threat ecosystem and broader Gh0stRAT-derived tooling.
Profile source: Mallory opens in a new tabValleyRAT
ValleyRAT, also referred to as Winos 4.0 or WinOS 4.0 in overlapping reporting, is a multi-stage Windows remote access trojan associated in multiple investigations with the Silver Fox threat ecosystem and broader Gh0stRAT-derived tooling. It has been active since at least 2023 and has been used in campaigns targeting Chinese- and Japanese-speaking users, Indian tax-related targets, and other victims through socially engineered delivery chains. Reported lures include tax-themed phishing, trojanized software installers, fake browser installers, and abuse of legitimate applications for DLL sideloading, including VLC-based chains. Some campaigns also used malicious disk images or compressed archives as intermediate stages.
C2 tracking
Derp observations, rolling seven-day window
Samples
0c2bd7774f104b7a4787b3300d8763e03bb08bddbb2967d34a2442e8a63befa0 948e500e26f5be7d2fae6ac14ccaf6fbdc56217db0fb25b9983a5439ba8eb883 e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43 0a3061ce09d7e3cb2b3d3453432da69ee83b59b782853d1f6462fd177db75a7a 367314385c4bc2f97e4a1d5b9a1612ec6f71ad0b51cf0754c19f7275f916e386 7813b7a31ac9f251e26156496d61c44b4b14aff5390b8212b050033975395d7c ec4ea2c3851c910fa98f99e2a3cf161022b4511a1c56e1fcc3a5d2e07542b279 40c98ff9673f67cfa82d9e2e16a2e55644f71fec87e2d92f25821a2b917f8145 9e189328af4d4277d728012f069b3f0997fc77a6a751aad1bacea94df2059a64 b1dd9ebb57480de3da86e683639b328e9dcf291b4bd2d4816986d1b0cdfa9342 Reported operators
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The malware, tracked as ValleyRAT, is deployed by a hacking group known as SilverFox, and it stands out for one reason: it refuses to stop at just one payload.
Seqrite said it identified infrastructure and tactical overlaps with Silver Fox, a Chinese cybercrime group previously attributed to tax-themed phishing campaigns that deliver ValleyRAT.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
The threat actor also attempted to use a downloader built using the advanced malicious framework Winos4.0. The downloader, placed under drivers\etc masquerading as hosts.exe, attempted to connect to the IP address 154.201.68[.]57. After a successful connection, it downloads the payload and saves it into the registry key d33f351a4aeea5e608853d1a56661059. It then executes the payload.
Finally, this Proofpoint cybercrime analysis notes that the threat group continues to abuse the open-source Winos4.0 framework. In early 2026, researchers spotted a heavily modified variant featuring a massive codebase expansion.
Our investigation revealed that the delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant.
Analysts found infrastructure overlaps between this campaign and previous npm typosquatting attacks that distributed ValleyRAT (also known as Winos 4.0).
SHA256 Family Relation 2cb5614936ef42e52c44ebb7b758bf57fde6c7b2d68cc21a7ec94d2f0adb3435 SilverFox / Winos4.0 Qt loader (yesterday's sample) Compiled 2026-04-08; lists Alibaba Cloud HK IPs including nodes in this cluster. | A published timeline showing the operator has been running on this namespace continuously since March 2025, and that yesterday's ValleyRAT ZPAQ sample (2cb56149…) is bound to this same infrastructure cluster.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
The sample delivers ValleyRAT with a kernel-mode rootkit and employs a six-stage infection chain built around a legitimate zpaqfranz decompression binary used as a LOLBin, a ByteDance/TikTok elevation service binary used as a DLL sideloading host, and a vulnerable wnBios BIOS driver used via BYOVD for physical memory access.
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
Associated Analytic Story DarkSide Ransomware ... LockBit Ransomware ... Ransomware ... ValleyRAT
Exploited software
MITRE ATT&CK
Reporting
Winos 4.03
Установка бэкдоров - RAT для долгосрочного контроля (Winos4.0, SectopRAT, Oyster) ... вредоносное ПО семейства Winos4.0. ... Winos4.0 давал полный контроль: скриншоты, сбор системной информации, управление файлами, выполнение произвольного кода по команде C2.
Researchers identified a social engineering campaign impersonating the Indian Income Tax Department to deliver the ValleyRat Remote Access Trojan (RAT) through a multi-stage infection chain involving a malicious VHDX, DLL SideLoading, and encrypted in-memory payload execution.
The malware, tracked as ValleyRAT, is deployed by a hacking group known as SilverFox, and it stands out for one reason: it refuses to stop at just one payload.
Seqrite said it identified infrastructure and tactical overlaps with Silver Fox, a Chinese cybercrime group previously attributed to tax-themed phishing campaigns that deliver ValleyRAT.
Researchers have uncovered a campaign that abuses the popular VLC media player to quietly install ValleyRAT, a remote access trojan that gives attackers full control over infected computers.
Researchers have uncovered a campaign that abuses the popular VLC media player to quietly install ValleyRAT, a remote access trojan that gives attackers full control over infected computers.
The malware ValleyRAT, which is the focus of this report, has been repeatedly observed in the wild since it was first named by Proofpoint in 2023. As its name suggests, ValleyRAT is a Remote Access Trojan (RAT) that enables threat actors to remotely control compromised systems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.