ValleyRAT, also known as Winos 4.0, is a modular Windows remote-access Trojan first publicly reported in 2023. It provides remote command execution, file and process management, host profiling, surveillance, and data exfiltration. Its collection capabilities include DirectInput-based keylogging, clipboard capture, screenshots, active-window monitoring, and detailed hardware and operating-system information. Operators can download and execute additional DLL or shellcode modules, update command-and-control configuration, clear logs, and reboot or shut down compromised systems.
Distribution includes phishing emails, counterfeit software-download websites, SEO-poisoned search results, and trojanized installers impersonating legitimate applications. Campaigns have used invoice and Indian tax-notice lures, as well as modified QN Wallpaper packages disguised as popular software installers. Infection chains frequently abuse signed applications for DLL sideloading, decrypt payloads, and load ValleyRAT into memory. Some chains deploy vulnerable signed kernel drivers to terminate endpoint-security processes, remove user-mode API hooks, and inject payloads into Windows service processes.
ValleyRAT performs virtualization and analysis-tool checks and supports process injection and process hollowing. Persistence mechanisms observed across deployments include autorun configuration, Startup-folder entries, scheduled tasks, and watchdog routines that restore stopped components. Configurable process protection can mark the malware as critical, potentially causing a system crash if it is forcibly terminated.
ValleyRAT is frequently associated with Silver Fox, whose operations include espionage and financially motivated activity, but its use alone does not establish attribution. Observed targeting includes users and organizations in China and India and a Japanese industrial manufacturer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Driver file wsftprm.sys — Vulnerable signed driver associated with CVE-2023-52271. The campaign uses vulnerable signed kernel drivers to terminate protected antivirus and endpoint-security processes.
"It's worth noting that the NSecKrnl driver is susceptible to a known security flaw (CVE-2025-68947, CVSS score: 5.7) that could be exploited to terminate arbitrary processes."
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
When the 0x0A command is received ... the specified value is deleted using RegDeleteValueW ... [and] stored as REG_BINARY using RegSetValueExW.
When the parameter is 0, it retrieves the path of the current executable and copies itself to the Programs directory under the Windows Start Menu using the name GFIRestart32.exe. When the parameter is 1, it opens the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key and checks whether an autorun value named GFIRestart32.exe exists.
Téléchargement et exécution de modules supplémentaires (DLL ou shellcode via process hollowing sur svchost).
When the parameter is 0, it retrieves the path of the current executable and copies itself to the Programs directory under the Windows Start Menu using the name GFIRestart32.exe. When the parameter is 1, it opens the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key and checks whether an autorun value named GFIRestart32.exe exists.
Various character strings embedded in the sample are reversed using the _wcsrev function, making them readable... C2 IP addresses ... port numbers ... are obtained in plaintext.
The malicious DLL extracts an encrypted ValleyRAT payload from a PeLoader file or from the DLL resources; both variants are encrypted with AES.
“[A] malicious installer disguised as a KakaoTalk installer” and “Malicious file names and creation paths consisted of random strings.”
Quel que soit le nom, l’installateur déploie une version modifiée de QN Wallpaper, un outil chinois de gestion de fonds d’écran (adware légitime).
Téléchargement et exécution de modules supplémentaires (DLL ou shellcode via process hollowing sur svchost).
Sélectionne l’un de deux payloads AES-chiffrés ... valide les en-têtes PE, charge le payload en mémoire et transfère le contrôle via DllMain.
The malware uses the PathIsDirectoryA API to check whether the C:\Program Files\VMware\VMware Tools\ directory exists... If total RAM is below approximately 1.1 GB... [or] disk capacity is below approximately 110 GB, the program assumes that the environment may be a virtual machine and terminates itself.
When the 0x0A command is received ... the specified value is deleted using RegDeleteValueW ... [and] stored as REG_BINARY using RegSetValueExW.
CuboidalCanine... uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls.
The application uses the GetForegroundWindow and GetWindowTextW APIs to retrieve the title of the user's active window.
The malware obtains the processor model information by reading the ProcessorNameString value under the HARDWARE\DESCRIPTION\System\CentralProcessor\0 Registry key.
The malware checks a predefined list of process names ... running processes are enumerated using the CreateToolhelp32Snapshot, Process32FirstW, and Process32NextW APIs.
The resulting information is used for profiling the victim system and transmitting the data to the C2 server.
The malware uses the GetLocalTime API to retrieve the system's local date and time information.
The malware uses the PathIsDirectoryA API to check whether the C:\Program Files\VMware\VMware Tools\ directory exists... If total RAM is below approximately 1.1 GB... [or] disk capacity is below approximately 110 GB, the program assumes that the environment may be a virtual machine and terminates itself.
952 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
197 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular backdoor deployed as the final payload in the Silver Fox campaign. It supports remote surveillance, command execution, and data exfiltration. The campaign's loaders disable endpoint defenses using signed kernel drivers before deploying ValleyRAT.
A remote-access trojan downloaded by the malicious DLL after DLL side-loading.
Mentioned only as a known Silver Fox-associated malware family in an attribution comparison.
Mentioned as a final payload associated with documented Silver Fox activity for comparison with this campaign’s VenomRAT payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.