Researchers Identify ValleyRAT Malware Targeting Chinese-Speaking Users

26 Aug 2024

ValleyRAT's Intricate Mechanism

Researchers at ANY.RUN have recently unveiled a sophisticated cyberattack specifically targeting Chinese-speaking users. This attack employs a multi-stage malware known as ValleyRAT, designed to infiltrate systems and establish persistent backdoors, enabling attackers to monitor and control compromised devices.

Once installed, ValleyRAT deploys additional plugins that enhance its capabilities, potentially leading to severe consequences such as data exfiltration, ransomware incidents, or the formation of botnets. The implications of this malware are particularly alarming for Chinese-speaking individuals and organizations, underscoring the urgent need for robust cybersecurity measures and heightened vigilance against such sophisticated threats.

The cyber campaign, first detected in June 2024, utilizes email messages containing malicious URLs that link to compressed executables harboring the ValleyRAT malware. This threat is particularly adept at evading detection by executing directly in memory, making it a formidable adversary.

ValleyRAT’s design allows for persistence and privilege escalation, enabling it to maintain a foothold on compromised systems and gain unauthorized access to sensitive information. The campaign continues to evolve, employing refined techniques to enhance its impact and evade detection.

Details of the Attack Chain

The attack chain initiates with a malicious executable masquerading as a legitimate application. Upon execution, it drops a decoy document and loads shellcode to establish a connection with a command-and-control (C2) server.

From this server, it downloads components such as RuntimeBroker and RemoteShellcode, which are instrumental in achieving persistence and administrative privileges. By exploiting vulnerabilities in legitimate binaries like fodhelper.exe and the CMSTPLUA COM interface, attackers further escalate their privileges on the compromised system.

RuntimeBroker serves as a secondary loader, tasked with fetching additional malware from a remote C2 server, thereby initiating a new infection cycle while incorporating safeguards to detect and evade virtual environments.

In a targeted approach, the malware scans the Windows Registry for specific keys associated with popular Chinese applications such as Tencent, WeChat, and Alibaba DingTalk, reinforcing its focus on Chinese systems.

RemoteShellcode functions as a downloader for ValleyRAT. Upon execution, it establishes a network connection with a command-and-control server using either UDP or TCP protocols, facilitating the transfer of the ValleyRAT payload. Once received, this payload grants attackers remote control over the compromised system.

Capabilities and Implications

The capabilities of ValleyRAT are extensive, including remote code execution, screenshot capture, file management, and the ability to load additional plugins, rendering it a significant threat to cybersecurity.

ANY.RUN’s sandbox proves to be an invaluable tool for analyzing ValleyRAT’s behavior. It identified that MSBuild.exe was executing a file in the Temp directory. While MSBuild is a legitimate component for building .NET projects, its usage in this context suggests an attempt to obfuscate malicious activity.

Detection rules from Suricata IDS within the sandbox indicate that attempts to communicate with a command-and-control server point towards a potential malware infection, utilizing legitimate tools and hidden communication channels.

Are You From SOC/DFIR Teams? – Try Advanced Malware and Phishing Analysis With ANY.RUN – 14-day free trial

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4933611
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
823809
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
417833
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
303242
downloads

News and reviews for Desktop Windows

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more