Fake Huorong Site Distributes ValleyRAT Backdoor to Users

Fake Huorong Site Distributes ValleyRAT Backdoor to Users

First seen 24 Feb 2026, 07:08 UTC MalwarebytesGbhackersCybersecuritynews 82% similarity 48.0

Article Content

Browse articles
ThreatCluster

A fraudulent Huorong security website has been identified as a source of the ValleyRAT backdoor, which compromises user systems. The malware campaign targets users who mistakenly visit the malicious site, which is only slightly different from the legitimate Huorong domain. This incident highlights the risks associated with typosquatting in cybersecurity.

ThreatCluster AI

Timeline

2026-02-23
Malwarebytes reports on fake Huorong site infecting users
2026-02-24
GBHackers publishes article on ValleyRAT backdoor campaign

Community

Browse all →

Tracked Entities in This Story