ValleyRAT

Aliases: Winos

First seen
2021-09-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 00:38:18
Profile updated
2026-07-07 13:13:51

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:kr

Context

ValleyRAT, also known as Winos, is a remote access trojan primarily used for cyber-espionage. It has been observed targeting government and technology sectors in East Asia and facilitates remote control through command-and-control servers, allowing attackers to steal sensitive information.

Detection coverage

  • 4 YARA rules

Detection rules

  • SEKOIA_Malware_Valleyrat_Strings_Config (yara-rule)
  • SEKOIA_Malware_Valleyrat_Downloader_Strings (yara-rule)
  • SEKOIA_Malware_Valleyrat_1Ststage_Strings (yara-rule)
  • MALPEDIA_Win_Winos_Auto (yara-rule)

Reports & references

  • Trend Micro — Behind The Great Wall Void Arachne Targets Chinese Speaking User (report)
  • Palo Alto Unit 42 — Espionage Campaign Targets South Asian Entities (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • cyderes.com — Chrome Installer Impersonation Campaign Targets China Based Victims With Valleyrat Trojan (report)
  • proofpoint.com — Chinese Malware Appears Earnest Across Cybercrime Threat Landscape (report)
  • netresec.com (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Valley Rat (report)
  • research.checkpoint.com — Cracking Valleyrat From Builder Secrets To Kernel Rootkits (report)
  • any.run — Valleyrat (report)
  • zscaler.com — Technical Analysis Latest Variant Valleyrat (report)
  • cloudsek.com — Silver Fox Targeting India Using Tax Themed Phishing Lures (report)
  • x.com — 1892458955189686553 (report)
  • fortinet.com — Winos Spreads Via Impersonation Of Official Email To Target Users In Taiwan (report)
  • apophis133.medium.com — Valleyrat S2 Chinese Campaign 4504B890F416 (report)
  • research.checkpoint.com — Silver Fox Apt Vulnerable Drivers (report)
  • rapid7.com — New Cleversoar Installer Targets Chinese And Vietnamese Users (report)
  • hexastrike.com — Valleyrat Exploiting Byovd To Kill Endpoint Security (report)
  • esentire.com — Winos4 0 Online Module Staging Component Used In Cleversoar Campaign (report)
  • secrss.com — 52018 (report)
  • hexastrike.com — Silver Fox Exploiting Byovd To Kill Endpoint Security (report)
  • labs.k7computing.com — Fake Microsoft Teams Campaign Delivers Valleyrat Via Nsis Installer And Dll Sideloading (report)

External references