ZeroHour
Kaspersky Securelistpublished ()ingested Pavel Bukhtenko

ValleyRAT masquerading as adware

mediumMalware exploited in the wildimportance 45
AI summary · glm-5.3-flash

Kaspersky reports threat actors distributing the ValleyRAT backdoor disguised as adware, tracing the infection chain to the final payload.

Kaspersky researchers analyzed a campaign distributing the ValleyRAT backdoor under the guise of adware. The write-up documents the complete infection chain, from the malicious installer through deployment of the final backdoor payload. ValleyRAT is a remote access tool typically used by criminal actors for surveillance and data theft.

  • ValleyRAT distributed while masquerading as adware
  • Analysis covers the full infection chain
  • Malicious installer leads to final backdoor payload
VendorsKaspersky
MalwareValleyRAT
OrganizationsKaspersky
Full article

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

This source does not provide full text. Read it at securelist.com.