ValleyRat is a malware family tracked across 19 threat clusters and 35 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity July 20, 2026.
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
A new variant of Chaos malware, originally targeting routers, has been observed exploiting misconfigured Linux cloud servers. This development was documented by Darktrace's CloudyPots program, which captures attacker…
The Silver Fox cyber threat group is conducting a targeted spearphishing campaign against Japanese businesses, particularly manufacturers, during the annual tax filing and corporate restructuring season. The attackers…
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number…
The SilverFox APT group has upgraded its ValleyRAT malware into a sophisticated eight-stage malware chain, culminating in a kernel-mode rootkit. This evolution enhances post-exploitation persistence and evasion…
A new malware campaign linked to the Silver Fox APT group has been identified, utilizing a fake Chinese language pack installer for Telegram to deliver ValleyRAT, a sophisticated remote access trojan. The malicious MSI…
The cybercriminal group TA4922, identified as Chinese-speaking, has been deploying an expanding range of malware including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. These campaigns are financially…
The Silver Fox APT group has launched a campaign targeting users in China by distributing malware through fake installers of popular applications, including Microsoft Teams. The malware, known as ValleyRAT, employs…
A fraudulent Huorong security website has been identified as a source of the ValleyRAT backdoor, which compromises user systems. The malware campaign targets users who mistakenly visit the malicious site, which is only…