ValleyRAT is a sophisticated Remote Access Trojan attributed to the Silver Fox APT group, leveraging advanced evasion techniques to target high-value sectors like finance and healthcare. Its stealth and persistence make it difficult to detect with traditional security tools, prompting calls for preemptive cyber defense strategies. Affected: finance, healthcare, manufacturing, critical infrastructure
Keypoints :
- ValleyRAT is a new Remote Access Trojan discovered in early 2023.
- It operates entirely in memory, making detection and removal challenging.
- Utilizes techniques such as DLL side-loading, process injection, and living-off-the-land binaries.
- Target sectors include finance, healthcare, manufacturing, and critical infrastructure.
- Employs legitimate-looking infrastructure for malware distribution to evade detection.
- Recent variants have incorporated keylogging functionality and enhanced evasion techniques.
- Strongly attributed to the Silver Fox APT group with evidence of their shared tactics with Gh0stRAT.
- Traditional detection-based security tools are inadequate against ValleyRAT’s stealth methods.
- Organizations need to adopt preemptive cyber defense strategies to combat advanced threats.
- ValleyRAT represents a trend toward more sophisticated and persistent cyber threats.
MITRE Techniques :
- Process Injection (T1055): The malware uses process injection to execute code stealthily in existing processes like svchost.exe.
- DLL Side-Loading (T1218.011): Utilizes DLL side-loading through legitimate applications such as Douyin.exe.
- Living off the Land (T1203): Leverages legitimate system binaries (e.g., nslookup.exe) to execute malicious code in memory.
- Indicator Removal on Host (T1070): Attempts to delete logs or indicators of compromise by executing code in memory without leaving traces.
Indicator of Compromise :
- [Domain] anizom[.]com
- [Domain] karlost[.]club
- [File] sscronet.dll
- [File] douyin.exe
- [Hash SHA-256] 53A6735CE1ECA68908C0367152A1F8F3CA62B801788CD104F53D037811284D71
Full Story: https://www.morphisec.com/blog/valleyrat-malware-and-the-evolving-landscape-of-ransomware-threats/