PULSE NAME
Rat Race: ValleyRAT Malware Targets Organizations with New Delivery Techniques
WHITE Silver Fox APT AlienVault 2025-02-05 Modified: 2025-03-07
5
IOCs
LOW VOLUME
ValleyRAT, a sophisticated multi-stage malware attributed to Silver Fox APT, has updated its tactics, techniques, and procedures. The malware targets key roles in finance, accounting, and sales departments using phishing emails, malicious websites, and instant messaging platforms. The infection chain begins with a fake Chrome browser download, followed by the execution of a Setup.exe file that downloads additional components. The malware employs DLL side-loading, process injection, and anti-VM techniques to evade detection. It includes features such as keylogging, screen monitoring, and persistence mechanisms. ValleyRAT communicates with command and control servers and can execute various commands, including dropping and executing files, setting startup configurations, and manipulating processes.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ValleyRAT GhostRAT
Indicators of Compromise (2 / 5 total)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 53a6735ce1eca68908c0367152a1f8f3ca62b801788cd104f53d037811284d71 2025-02-05
FileHash-SHA256 968b976167b453c15097667b8f4fa9e311b6c7fc5a648293b4abd75d80b15562 2025-02-05