Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 19, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
WinOS, also known as ValleyRAT, is a Windows remote access trojan associated with the Silver Fox malware ecosystem and broader Chinese-language cybercrime activity.
Profile source: Mallory opens in a new tabWinos
WinOS, also known as ValleyRAT, is a Windows remote access trojan associated with the Silver Fox malware ecosystem and broader Chinese-language cybercrime activity. It has been distributed through counterfeit software installers and phishing-style download pages masquerading as popular applications and utilities, including fake Flash updates, translation tools, office software, browsers, and VPN software. Reported distribution methods include phishing websites, fake software download portals, SEO-driven lures, email, and instant messaging, with campaigns observed across Asia.
WinOS is a modular trojan designed for remote control and data theft on compromised hosts. Documented capabilities include plugin-based extensibility, screenshot capture, keylogging, clipboard theft, and broader remote-control functionality. Its modular architecture has enabled continued reuse and adaptation by multiple threat groups. In observed Windows infection chains, installer packages ultimately deploy the trojan after staging components that execute additional payloads and establish persistence through autorun mechanisms.
The malware has been described as one of the most common trojans used in Silver Fox operations. Reporting indicates that leaked source code contributed to wider redevelopment and reuse beyond a single operator, including adoption by cybercrime groups and some APT-linked actors. WinOS has therefore evolved from a family associated with one cluster into a more broadly reused malware platform within the Chinese threat landscape.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.
Both types ultimately release the Winos Trojan.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.