Gbhackers
Fake Huorong Site Distributes ValleyRAT Backdoor to Users
First seen 24 Feb 2026, 07:08 UTC
•

•82% similarity
•48.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A fraudulent Huorong security website has been identified as a source of the ValleyRAT backdoor, which compromises user systems. The malware campaign targets users who mistakenly visit the malicious site, which is only slightly different from the legitimate Huorong domain. This incident highlights the risks associated with typosquatting in cybersecurity.
ThreatCluster AI
Timeline
2026-02-23
Malwarebytes reports on fake Huorong site infecting users
2026-02-24
GBHackers publishes article on ValleyRAT backdoor campaign