ValleyRAT Campaign Uses Fake Installers and Japanese Malicious Emails to Infect Windows Users

ValleyRAT, a potent Remote Access Trojan (RAT) first identified in 2023, is experiencing a massive resurgence across the threat landscape.

Threat intelligence from LevelBlue GSOC reveals that detection volumes skyrocketed throughout 2025 and doubled in pace by early 2026.

Historically linked to the SilverFox threat group, this malware allows attackers to take full remote control of compromised Windows systems.

While earlier campaigns relied heavily on fake installers targeting Chinese-speaking users, recent operations have pivoted to malicious emails designed to ensnare Japanese-speaking victims.

These dual attack vectors highlight a highly adaptable threat actor actively expanding its geographical reach.

The fake installer method actively interferes with regional security software, often serving as a beachhead into the overseas branches of multinational corporations.

ValleyRAT activity that progressed or was successful as detected by LevelBlue’s GSOC from January 2025 to April 2026 (Source: levelblue)
ValleyRAT activity that progressed or was successful as detected by LevelBlue’s GSOC from January 2025 to April 2026 (Source: levelblue)

However, the newly discovered malicious email campaign introduces entirely different tactics.

By blending social engineering with advanced fileless execution techniques, the attackers have created an infection chain that effortlessly bypasses traditional endpoint defenses.

ValleyRAT Infects Windows Users

The latest ValleyRAT campaign initiates attacks via highly targeted phishing emails written in Traditional Chinese or Japanese.

These messages typically masquerade as urgent internal communications discussing personnel transfers or salary adjustments.

When a victim clicks the embedded link, they download a ZIP archive containing a legitimate, digitally signed executable and a malicious DLL.

The email explicitly instructs the recipient to open the files on a computer, setting the stage for a classic DLL sideloading attack.

ValleyRAT fake installer attack chain (Source: levelblue)
ValleyRAT fake installer attack chain (Source: levelblue)

Once the victim launches the seemingly harmless executable often disguised as VLC media player it unknowingly loads the malicious DLL.

This DLL acts as the orchestrator of the attack, first establishing persistence by copying itself into public directories and creating registry run keys.

It then executes a highly sophisticated routine to download the final ValleyRAT payload from a remote server.

To avoid triggering alarms, the download URL is Base64-encoded, and the payload is encrypted with the RC4 algorithm using the key “zenzensu.”

According to LevelBlue research, detecting a fileless, memory-resident threat like ValleyRAT requires more than just traditional signature-based scanning.

Security analysts have successfully tracked this campaign by hunting for specific module names extracted from leaked ValleyRAT source code on GitHub.

By monitoring for these floating modules in memory, defenders can spot the malware even after it has evaded initial endpoint checks.

Because this method can generate false positives, it is best used in proactive threat-hunting environments rather than in automated alert systems.

ValleyRAT Indicators of Compromise

IOCIOC TypeDescription
e8be03f19ada1f5cec74b143e21d4939e781671dSHA1Malicious email
frehf.oss-cn-hongkong.aliyuncs[.]comDomainDomain part of the URL in the malicious email
65168c8dd93b16d3b77092fb70c0fa6fba4dffccSHA1ZIP archive

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories