Skip to content

ValleyRAT

ValleyRAT, also known as Winos 4.0, is a modular Windows backdoor with remote-control, surveillance, reconnaissance, and payload-delivery capabilities.

Profile source: Mallory opens in a new tab

ValleyRAT

Family profile

ValleyRAT, also known as Winos 4.0, is a modular Windows backdoor with remote-control, surveillance, reconnaissance, and payload-delivery capabilities. It collects host details, active-window information, keystrokes, clipboard contents, and screenshots, and can exfiltrate collected keylogging and clipboard data. Operators can issue commands to reboot or shut down the host, clear logs, update command-and-control configuration, and retrieve additional DLL or shellcode modules. Downloaded shellcode may be executed through process hollowing, and the malware can inject into a Windows process to recover execution after termination.

ValleyRAT uses defense-evasion and resilience features including encrypted in-memory payload loading, security- and traffic-analysis tool discovery, critical-process protection that can crash the host if forcibly terminated, and configuration obfuscation. Observed delivery chains have trojanized the legitimate QN Wallpaper application, abusing DLL sideloading through signed executables to load an encrypted ValleyRAT payload in memory. Associated installers establish autorun persistence, attempt to disable Microsoft Defender, and may seek elevated privileges.

ValleyRAT has been observed in campaigns affecting users primarily in China and India, as well as phishing activity targeting organizations in Japan and Indian taxpayers. Activity involving the QN Wallpaper delivery chain has been assessed as likely linked to the China-nexus Silver Fox threat actor, although ValleyRAT attribution is not exclusive because the family has been used by multiple actors.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
61 IP / 17 hostnames

Leading locations

  • HK55
  • US11
  • CN4
  • SG3
  • CH1
  • ID1
  • JP1
  • MY1
  • NL1

Leading providers

  • CTG Server Limited19
  • Alibaba (US) Technology Co., Ltd.7
  • Amazon.com, Inc.6
  • Turing Group Limited4
  • Cloudflare, Inc.3
  • Cloudie Limited3

Infrastructure traits

  • Hosting 71
  • Anycast 3

Samples

Recent associated samples

Reported operators

Threat actors

14 named in public reporting
Silver Fox

Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.

GoldenEyeDog

Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.

CuboidalCanine

Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.

TA4922

...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.

TA428

Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.

APT SilverFox

The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.

APT41

The threat actor also attempted to use a downloader built using the advanced malicious framework Winos4.0. The downloader, placed under drivers\etc masquerading as hosts.exe, attempted to connect to the IP address 154.201.68[.]57. After a successful connection, it downloads the payload and saves it into the registry key d33f351a4aeea5e608853d1a56661059. It then executes the payload.

SwimSnake

Analysts found infrastructure overlaps between this campaign and previous npm typosquatting attacks that distributed ValleyRAT (also known as Winos 4.0).

APT-Q-27

SHA256 Family Relation 2cb5614936ef42e52c44ebb7b758bf57fde6c7b2d68cc21a7ec94d2f0adb3435 SilverFox / Winos4.0 Qt loader (yesterday's sample) Compiled 2026-04-08; lists Alibaba Cloud HK IPs including nodes in this cluster. | A published timeline showing the operator has been running on this namespace continuously since March 2025, and that yesterday's ValleyRAT ZPAQ sample (2cb56149…) is bound to this same infrastructure cluster.

CL-STA-0048

A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.

UTG-Q-1000

A Japanese-language invoice campaign impersonating Rakuten dropped a ValleyRAT implant on April 16, 2026.

The Great Thief of Valley

The sample delivers ValleyRAT with a kernel-mode rootkit and employs a six-stage infection chain built around a legitimate zpaqfranz decompression binary used as a LOLBin, a ByteDance/TikTok elevation service binary used as a DLL sideloading host, and a vulnerable wnBios BIOS driver used via BYOVD for physical memory access.

Valley Thief

The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).

MuddyWater

Associated Analytic Story DarkSide Ransomware ... LockBit Ransomware ... Ransomware ... ValleyRAT

Exploited software

Vulnerabilities linked to ValleyRAT

2 CVEs

MITRE ATT&CK

ValleyRAT in ATT&CK

108 distinct techniques

Techniques

108 techniques
T1189 Drive-by Compromise T1113 Screen Capture T1082 System Information Discovery T1057 Process Discovery T1553.002 Code Signing T1115 Clipboard Data T1056.001 Keylogging T1036 Masquerading T1105 Ingress Tool Transfer T1070.001 Clear Windows Event Logs T1620 Reflective Code Loading T1027.013 Encrypted/Encoded File T1547 Boot or Logon Autostart Execution T1010 Application Window Discovery T1548 Abuse Elevation Control Mechanism T1055 Process Injection T1055.012 Process Hollowing T1529 System Shutdown/Reboot T1562.001 Disable or Modify Tools T1005 Data from Local System T1027 Obfuscated Files or Information T1074.001 Local Data Staging T1016 System Network Configuration Discovery T1112 Modify Registry T1518.001 Security Software Discovery T1546.001 Change Default File Association T1547.001 Registry Run Keys / Startup Folder T1548.002 Bypass User Account Control T1123 Audio Capture T1204.002 Malicious File T1140 Deobfuscate/Decode Files or Information T1059.005 Visual Basic T1083 File and Directory Discovery T1059.003 Windows Command Shell T1090.001 Internal Proxy T1053.005 Scheduled Task T1566.002 Spearphishing Link T1219 Remote Access Tools T1497.001 System Checks T1046 Network Service Discovery T1608.006 SEO Poisoning T1562.004 Disable or Modify System Firewall T1543.003 Windows Service T1566.001 Spearphishing Attachment T1566 Phishing T1572 Protocol Tunneling T1584 Compromise Infrastructure T1053 Scheduled Task/Job T1543 Create or Modify System Process T1125 Video Capture T1553 Subvert Trust Controls T1014 Rootkit T1574 Hijack Execution Flow T1562 Impair Defenses T1560 Archive Collected Data T1070 Indicator Removal T1055.003 Thread Execution Hijacking T1068 Exploitation for Privilege Escalation T1071 Application Layer Protocol T1129 Shared Modules T1037 Boot or Logon Initialization Scripts T1071.001 Web Protocols T1041 Exfiltration Over C2 Channel T1564.004 NTFS File Attributes T1218.011 Rundll32 T1036.005 Match Legitimate Resource Name or Location T1204.001 Malicious Link T1204 User Execution T1106 Native API T1059.001 PowerShell T1070.004 File Deletion T1027.002 Software Packing T1528 Steal Application Access Token T1574.001 DLL T1027.003 Steganography T1559.001 Component Object Model T1497 Virtualization/Sandbox Evasion T1497.003 Time Based Checks T1211 Exploitation for Defense Evasion T1012 Query Registry T1490 Inhibit System Recovery T1055.002 Portable Executable Injection T1195.002 Compromise Software Supply Chain T1614 System Location Discovery T1095 Non-Application Layer Protocol T1021.003 Distributed Component Object Model T1027.007 Dynamic API Resolution T1562.009 Safe Mode Boot T1222.001 Windows File and Directory Permissions Modification T1566.003 Spearphishing via Service T1573 Encrypted Channel T1036.004 Masquerade Task or Service T1090.003 Multi-hop Proxy T1074 Data Staged T1070.006 Timestomp T1134.002 Create Process with Token T1195 Supply Chain Compromise T1218 System Binary Proxy Execution T1059.007 JavaScript T1583.001 Domains T1547.006 Kernel Modules and Extensions T1608.001 Upload Malware T1571 Non-Standard Port T1564.009 Resource Forking T1104 Multi-Stage Channels T1120 Peripheral Device Discovery T1562.010 Downgrade Attack T1059 Command and Scripting Interpreter

Reporting

Research mentioning ValleyRAT

Aug 31
Malware News

ValleyRAT masquerading as adware - Malware News - Malware Analysis, News and Indicators

A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.

Aug 31
Securelist

ValleyRAT is spreading disguised as adware | Securelist

Aug 14
Gurucul Threat Research

PATCHCORD: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure | Community Portal | Gurucul

Researchers reported an active cyber espionage campaign linked with moderate confidence to APT36 (Transparent Tribe) that is targeting telecom, government, defense, energy, and other critical infrastructure organizations across South Asia, including lures tied to Afghan Telecom, government updates, and software installers. The operation uses a malware cluster that includes HACKERAI C2 Agent, PATCHCORD, and SHEETCORD, showing an evolution from earlier custom C/C++ tooling to newer Go-based implants. The malware uses legitimate cloud services as covert command-and-control channels, with HACKERAI abusing GitHub Gists and SHEETCORD using Google Sheets for command traffic and possible data exfiltration. Researchers said HACKERAI can gather system information, execute remote commands, and maintain persistence by modifying browser shortcuts while still opening the legitimate browser to avoid suspicion; published defensive leads include suspicious GitHub activity, altered browser shortcuts, malicious ZIP or installer files, and a set of reported IOCs including domains, an IP address, and multiple SHA-256 hashes.

Aug 14
Cyber Security News

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

Aug 13
Acronis

PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

Aug 5
Cloud Security Alliance

New Chaos Malware Variant Exploiting Misconfigurations | CSA

Researchers reported that a new Chaos malware variant was deployed through a misconfigured Apache Hadoop instance, where an attacker abused an application-creation endpoint to execute shell commands, download a 64-bit ELF payload from pan.tenire[.]com, run it, and then remove it from disk. The intrusion, observed in Darktrace’s CloudyPots honeypot environment, shows Chaos moving beyond its earlier focus on routers and into Linux cloud-server compromises. The sample was identified as an evolved form of the Go-based Chaos malware previously described as a multi-purpose "Swiss army knife" threat. It retained DDoS and persistence functions while adding a SOCKS5 proxy capability and dropping some older spreading and exploitation features. Analysts said it established persistence with systemd, used a keep-alive script at /boot/system.pub, and relied on the embedded domain gmserver.osfc[.]org[.]cn for command-and-control resolution over port 65111, underscoring the risk posed by exposed or misconfigured cloud services.

Jul 27
Catonetworks

Previously Undocumented NinjaOne RMM Abuse Chain| Cato Networks

Threat actors in multiple intrusions abused Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint protections from kernel mode after gaining access through phishing or compromised remote-access credentials. Huntress reported an intrusion that began with stolen SonicWall SSLVPN credentials and escalated into deployment of an EDR killer built around a legitimate EnCase forensic driver, which Windows loaded despite the driver’s expired and revoked certificate. The malware hid the embedded driver with a 256-word substitution scheme, installed it as a kernel service with OEM-like naming, and repeatedly terminated a hashed list of 59 security processes before responders disrupted the attack ahead of ransomware deployment. Separate research tied similar tradecraft to SilverFox, which used vulnerable or signed drivers including BootRepair.sys, EnPortv.sys, wsftprm.sys, and a Microsoft-signed WatchDog Antimalware driver derived from the Zemana SDK to kill protected security processes and deliver ValleyRAT/Winos. Cato documented a campaign against a Japanese industrial manufacturer that used invoice-themed phishing, abused QQ and Tencent Cloud for delivery, and sideloaded a malicious PDFCORE8.dll through legitimate ConvertToPDF.exe and PDFDirect.exe; Check Point found SilverFox also adapted quickly to blocklists by modifying a single byte in an unauthenticated Authenticode timestamp area, preserving a valid Microsoft signature while changing the file hash. The combined reporting shows attackers increasingly pairing initial access with signed-driver abuse, DLL sideloading, and stealthy loaders to neutralize EDR before establishing persistent remote access.

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.