Summary: Morphisec Threat Lab has identified a new variant of the ValleyRAT malware that leverages advanced evasion techniques and multi-stage infection methods targeting high-value individuals, especially in finance and sales sectors. This malware is being distributed through phishing emails, messaging platforms, and compromised websites, with a notable new delivery method involving a fake Chinese telecom website. The complexity of this malware demonstrates the increasing sophistication of cyber threats from groups like Silver Fox APT.
Affected: Organizations in finance, accounting, and sales, particularly high-value individuals
Keypoints :
- New ValleyRAT variant uses a fake Chinese telecom website for distribution, employing a multi-stage infection chain.
- The malware evades detection using modified legitimate software and tactics to exploit system processes.
- Security measures need to be enhanced, including endpoint protection, employee training, and continuous monitoring.
Source: https://hackread.com/valleyrat-malware-variant-fake-chrome-downloads/