Security & Threat Intelligence · 31.08.2026, 10:17 UTC
ValleyRAT masquerading as adware
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | Securelist (Kaspersky) ↗ |
| Veröffentlicht | 31.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked. Some time ago, a client asked us to analyze a file with the MD5 hash c24e99f9437feacaa63766a3cde3fe3d and add it to our detection database. We initially classified it as adware, but a cursory analysis turned up suspicious network activity, which prompted us to dig deeper. It turned out the sample did far more than serve ads. In fact, its advertising functionality doesn’t even work; instead, it triggers an infection chain that delivers the ValleyRAT backdoor. Malicious installer The file the client shared with us turned out to be an installer that performed different actions depending on the two-letter suffix used in the file name, positioned just before the numeric string.
Installer name What it does
FS_SETUP_DD_173.exe Installs DingTalk, a workplace collaboration platform
FS_SETUP_GG_173.exe Installs Google Chrome
FS_SETUP_HY_173.exe Opens hxxps://meeting[.]tencent[.]com/download/
These actions are most likely designed to divert the user’s attention away from the sample’s malicious …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info USN-8689-1: OpenJDK 26 vulnerabilities
- info DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
- high Hunting MacSync Stealer infrastructure through behavioral pivots
- high When AI infrastructure becomes the target: Securing gateways and control points