ValleyRAT, also widely tracked as Winos 4.0, is a Windows remote access trojan associated primarily with Chinese-speaking cybercrime activity and repeatedly linked to clusters such as Silver Fox, TA4922, and a GoldenEyeDog subgroup. It has been used in financially motivated and espionage-adjacent operations targeting organizations and individuals across East and South Asia, including Japan, Russia, India, and Southeast Asia, with observed victim sectors including industrial manufacturing, gambling, government, finance, healthcare, hospitality, and other enterprises.
The malware is deployed to establish persistent remote access and support follow-on intrusion activity. Reported capabilities include command-and-control communications over a proprietary socket-based protocol, arbitrary command execution, file management, system information collection, screenshot capture, and broader remote administration functions consistent with long-term host control. In some campaigns, ValleyRAT has also been used as a delivery platform for additional malware, including custom backdoors. Operational reporting further describes full-control behavior associated with the Winos 4.0 family, including code execution and sustained operator access.
ValleyRAT is commonly delivered through phishing and social-engineering campaigns using invoice, tax, HR, bid, payroll, and business-themed lures, often localized to the target region and language. Observed delivery chains include malicious links, attachment-based phishing, abuse of legitimate file-sharing and cloud services, attacker-controlled landing pages, trojanized installers, ZIP archives, disk images, and DLL sideloading with legitimate signed executables. It has also been distributed through watering-hole activity and SEO-poisoning-driven fake software installers. Multiple loaders and packers have been observed in its ecosystem, including custom installer frameworks, Rust-based loaders, DONUTLoader, UUIDLoader, and the Cruciferra crypter service.
Recent campaigns show ValleyRAT embedded in sophisticated multi-stage intrusion chains featuring defense evasion and persistence mechanisms such as NTDLL unhooking, process injection, registry-based payload storage, scheduled tasks, dual watchdog recovery logic, and bring-your-own-vulnerable-driver techniques used to disable security controls from kernel mode. These tradecraft elements have been especially prominent in Silver Fox operations against Japanese organizations. Because ValleyRAT has reportedly been sold publicly and its builder has circulated openly, attribution cannot rely on the malware family alone; however, recurring overlaps in delivery chains, infrastructure patterns, code-signing abuse, and loader usage strongly connect many observed ValleyRAT campaigns to established Chinese-speaking threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-52271 documents how an affected version of wsftprm.sys can be abused to terminate protected processes.
"It's worth noting that the NSecKrnl driver is susceptible to a known security flaw (CVE-2025-68947, CVSS score: 5.7) that could be exploited to terminate arbitrary processes."
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Previous Silver Fox campaigns delivered ValleyRAT and Winos 4.0 through similar lure infrastructure, employing comparable persistence mechanisms and trojanized installer chains. | The group has a documented history of targeting Chinese-speaking populations through trojanized software, evolving its tooling from Gh0st RAT derivatives through ValleyRAT and Winos 4.0 to the current Atlas family.
...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.
CuboidalCanine (Expel-TA-0003): GoldenEyeDog’s ValleyRAT favoring subgroup... a faction of GoldenEyeDog stopped using their custom Gh0st RAT and moved to using ValleyRAT.
CuboidalCanine (Expel-TA-0003): GoldenEyeDog’s ValleyRAT favoring subgroup... a faction of GoldenEyeDog stopped using their custom Gh0st RAT and moved to using ValleyRAT.
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
CleverSoar employs a persistence mechanism by executing a scheduled task upon user login (T1053).
The DLL loader... is also responsible for unleashing a watchdog batch script that ensures persistence by means of a scheduled task...
After launching the second-stage executable, the malware starts cmd.exe and executes the watchdog script. The script repeatedly uses native Windows utilities... If the process is no longer present, the script relaunches the executable
CleverSoar employs a persistence mechanism by executing a scheduled task upon user login (T1053).
The DLL loader... is also responsible for unleashing a watchdog batch script that ensures persistence by means of a scheduled task...
After launching the second-stage executable, the malware starts cmd.exe and executes the watchdog script. The script repeatedly uses native Windows utilities... If the process is no longer present, the script relaunches the executable
CleverSoar employs a persistence mechanism by executing a scheduled task upon user login (T1053).
The DLL loader... is also responsible for unleashing a watchdog batch script that ensures persistence by means of a scheduled task...
...fetch shellcode that's injected into a new "svchost.exe" process using a technique called thread-context hijacking.
...fetch shellcode that's injected into a new "svchost.exe" process using a technique called thread-context hijacking.
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks... not before leveraging the BYOVD technique to obtain kernel access and impair security controls on the compromised host to evade detection.
These drivers, embedded within a malicious DLL, form a modular BYOVD framework for defense evasion.
The DLL contained hundreds of decoy exported functions pointing to junk code, with only one or two calling into the real routine... Payloads sat in the binary's .reloc section and were unpacked using one of over 90 encryption routines...
...fetch shellcode that's injected into a new "svchost.exe" process using a technique called thread-context hijacking.
...fetch shellcode that's injected into a new "svchost.exe" process using a technique called thread-context hijacking.
On top of that, the malware uses NTDLL unhooking to remove user-mode inline hooks placed by endpoint security software to keep tabs on native Windows API activity.
The malware integrates Bring Your Own Vulnerable Driver (BYOVD), DLL side-loading, NTDLL unhooking, process injection, registry-based payload storage, and two independent recovery mechanisms...
Even so, the surveillance features in its malware, including audio, webcam and keylogging capture, could be sold to or used by espionage actors.
Even so, the surveillance features in its malware, including audio, webcam and keylogging capture, could be sold to or used by espionage actors.
...communicates with an external server ("43.128.26[.]132") to fetch shellcode... The resulting final-stage implant is ValleyRAT... including command-and-control (C2) communication...
After establishing communication with its command-and-control server at: 43[.]128[.]26[.]132 the malware downloads shellcode
This technical analysis will cover the CleverSoar installer used to evasively deploy the Nidhogg rootkit, Winos4.0 framework and the custom backdoor (T1105).
706 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
168 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT mentioned only in connection with an infrastructure overlap on a separate server; the report explicitly states there is no evidence of operational coordination or attribution linkage.
Remote access trojan used by the CuboidalCanine subgroup of GoldenEyeDog, distributed via watering hole sites and commonly signed with abused code-signing certificates to bypass Windows SmartScreen.
Remote access trojan mentioned only as part of a separate campaign that previously used the same domain.
A remote access trojan used to establish persistent remote access on victim systems. In this campaign it is delivered via a phishing-initiated DLL side-loading chain and supported by BYOVD-based defense evasion, NTDLL unhooking, and a dual watchdog persistence design.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.