Skip to content
Fake Huorong Site Distributes ValleyRAT Backdoor to Users

Fake Huorong Site Distributes ValleyRAT Backdoor to Users

First seen 24 Feb 2026, 07:08 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A fraudulent Huorong security website has been identified as a source of the ValleyRAT backdoor, which compromises user systems. The malware campaign targets users who mistakenly visit the malicious site, which is only slightly different from the legitimate Huorong domain. This incident highlights the risks associated with typosquatting in cybersecurity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

Timeline

2026-02-23
Malwarebytes reports on fake Huorong site infecting users
2026-02-24
GBHackers publishes article on ValleyRAT backdoor campaign

More articles in this cluster (3)

Following this threat?

Track Silver Fox APT Group and ValleyRat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed