Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 38 IP / 77 hostnames
ValleyRAT, also known as Winos 4.0, is a Windows backdoor with remote-control, surveillance, data-collection, and modular payload-delivery functionality.
Profile source: Mallory opens in a new tabValleyRAT
ValleyRAT, also known as Winos 4.0, is a Windows backdoor with remote-control, surveillance, data-collection, and modular payload-delivery functionality. It has been distributed through trojanized software installers, including modified packages of the legitimate Chinese QN Wallpaper adware application. These chains abuse DLL sideloading to execute encrypted in-memory payloads under signed QN Wallpaper processes, while decoy installation behavior impersonates popular software or opens legitimate download pages. Other observed ValleyRAT activity has used phishing emails, tax and business-document lures, malicious download sites, archives, and disk-image files.
The backdoor collects host and active-window information, records keystrokes, captures clipboard contents and screenshots, and can transmit collected keylogger and clipboard data to its operators. It can identify analysis and security tools, clear logs, update command-and-control configuration, reboot or shut down the host, and retrieve and execute additional DLL or shellcode modules. Some variants use process injection or process hollowing involving Windows processes to execute modules or restore the backdoor, and may designate their process as critical, potentially causing a system crash when it is forcibly terminated. Observed persistence includes Startup-folder and file-association mechanisms. Installers have also attempted to weaken Microsoft Defender and obtain elevated execution through the Windows runas mechanism.
ValleyRAT activity has primarily affected users in China and India, with additional phishing activity observed against organizations in Japan and Indian taxpayers. Use of the family in multiple campaigns has been linked or assessed as likely linked to the China-nexus Silver Fox threat actor, though attribution is not conclusive for ValleyRAT generally because multiple actors may use the malware.
C2 tracking
Derp observations, rolling seven-day window
Samples
061c6607637a323d7cfec50defdd8eb2a4089daffca75654c81c22ad14054189 3ee1712f13467850e738a887f615a3e460d6d9b96c2a7081ab99ba91184fa2eb 41a95f0fbf308454d45f8c9b9482489d82d0cbaf417dde9ffafbeda22a8f81d9 69295616383f028750a18be9b641a22e28cff2bca8a19c2eabaa9395571c0d01 d5d0cc32ec49e441c279d635ccd05bc61630cdc5e90bffd03d92ec1de7ea4a6e fd80601fdaab4768691f7ddc9682ad59f51a2e0ce6515b7aaae9617a69e4c6c9 0fcc20a3bdfb89b516cab06ec7ce733b043c50b469e3f14c1b6904bda1b348c6 2ecf2e3a9be33fa90c02f0f985962d7277d622693c38adbfd1eb6c4e84238f89 344deae7427235fe11146b69b90cd88c836965d4125c80331499c466aeb94d99 7c57000213dd1091a61fa684cf838754627ac6fab63585ec9dd31074cb722602 Reported operators
Le backdoor ValleyRAT est déployé via une version modifiée de QN Wallpaper chargée par DLL sideloading. Il collecte les frappes, le presse-papiers, des captures d’écran et des informations système, et télécharge/exécute des modules supplémentaires.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
The threat actor also attempted to use a downloader built using the advanced malicious framework Winos4.0. The downloader, placed under drivers\etc masquerading as hosts.exe, attempted to connect to the IP address 154.201.68[.]57. After a successful connection, it downloads the payload and saves it into the registry key d33f351a4aeea5e608853d1a56661059. It then executes the payload.
Analysts found infrastructure overlaps between this campaign and previous npm typosquatting attacks that distributed ValleyRAT (also known as Winos 4.0).
SHA256 Family Relation 2cb5614936ef42e52c44ebb7b758bf57fde6c7b2d68cc21a7ec94d2f0adb3435 SilverFox / Winos4.0 Qt loader (yesterday's sample) Compiled 2026-04-08; lists Alibaba Cloud HK IPs including nodes in this cluster. | A published timeline showing the operator has been running on this namespace continuously since March 2025, and that yesterday's ValleyRAT ZPAQ sample (2cb56149…) is bound to this same infrastructure cluster.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.
The sample delivers ValleyRAT with a kernel-mode rootkit and employs a six-stage infection chain built around a legitimate zpaqfranz decompression binary used as a LOLBin, a ByteDance/TikTok elevation service binary used as a DLL sideloading host, and a vulnerable wnBios BIOS driver used via BYOVD for physical memory access.
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
Associated Analytic Story DarkSide Ransomware ... LockBit Ransomware ... Ransomware ... ValleyRAT
Exploited software
MITRE ATT&CK
Reporting
A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.
Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.
Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.
Threat actors in multiple intrusions abused Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint protections from kernel mode after gaining access through phishing or compromised remote-access credentials. Huntress reported an intrusion that began with stolen SonicWall SSLVPN credentials and escalated into deployment of an EDR killer built around a legitimate EnCase forensic driver, which Windows loaded despite the driver’s expired and revoked certificate. The malware hid the embedded driver with a 256-word substitution scheme, installed it as a kernel service with OEM-like naming, and repeatedly terminated a hashed list of 59 security processes before responders disrupted the attack ahead of ransomware deployment. Separate research tied similar tradecraft to SilverFox, which used vulnerable or signed drivers including BootRepair.sys, EnPortv.sys, wsftprm.sys, and a Microsoft-signed WatchDog Antimalware driver derived from the Zemana SDK to kill protected security processes and deliver ValleyRAT/Winos. Cato documented a campaign against a Japanese industrial manufacturer that used invoice-themed phishing, abused QQ and Tencent Cloud for delivery, and sideloaded a malicious PDFCORE8.dll through legitimate ConvertToPDF.exe and PDFDirect.exe; Check Point found SilverFox also adapted quickly to blocklists by modifying a single byte in an unauthenticated Authenticode timestamp area, preserving a valid Microsoft signature while changing the file hash. The combined reporting shows attackers increasingly pairing initial access with signed-driver abuse, DLL sideloading, and stealthy loaders to neutralize EDR before establishing persistent remote access.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.