ValleyRAT
Aliases: Winos
- First seen
- 2021-09-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:38:18
- Profile updated
- 2026-07-07 13:13:51
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:kr
Context
ValleyRAT, also known as Winos, is a remote access trojan primarily used for cyber-espionage. It has been observed targeting government and technology sectors in East Asia and facilitates remote control through command-and-control servers, allowing attackers to steal sensitive information.
Detection coverage
- 4 YARA rules
Detection rules
- SEKOIA_Malware_Valleyrat_Strings_Config (yara-rule)
- SEKOIA_Malware_Valleyrat_Downloader_Strings (yara-rule)
- SEKOIA_Malware_Valleyrat_1Ststage_Strings (yara-rule)
- MALPEDIA_Win_Winos_Auto (yara-rule)
Reports & references
- Trend Micro — Behind The Great Wall Void Arachne Targets Chinese Speaking User (report)
- Palo Alto Unit 42 — Espionage Campaign Targets South Asian Entities (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- cyderes.com — Chrome Installer Impersonation Campaign Targets China Based Victims With Valleyrat Trojan (report)
- proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
- netresec.com (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Valley Rat (report)
- research.checkpoint.com — Cracking Valleyrat From Builder Secrets To Kernel Rootkits (report)
- any.run — Valleyrat (report)
- zscaler.com — Technical Analysis Latest Variant Valleyrat (report)
- cloudsek.com — Silver Fox Targeting India Using Tax Themed Phishing Lures (report)
- x.com — 1892458955189686553 (report)
- fortinet.com — Winos Spreads Via Impersonation Of Official Email To Target Users In Taiwan (report)
- apophis133.medium.com — Valleyrat S2 Chinese Campaign 4504B890F416 (report)
- research.checkpoint.com — Silver Fox Apt Vulnerable Drivers (report)
- rapid7.com — New Cleversoar Installer Targets Chinese And Vietnamese Users (report)
- hexastrike.com — Valleyrat Exploiting Byovd To Kill Endpoint Security (report)
- esentire.com — Winos4 0 Online Module Staging Component Used In Cleversoar Campaign (report)
- secrss.com — 52018 (report)
- hexastrike.com — Silver Fox Exploiting Byovd To Kill Endpoint Security (report)
- labs.k7computing.com — Fake Microsoft Teams Campaign Delivers Valleyrat Via Nsis Installer And Dll Sideloading (report)