ValleyRAT Malware Identified by Delphos Labs

New threat intel. 60+ AV engines called this file clean. The Delphos Labs platform called it ValleyRAT in five minutes, a full day before the first signature landed. A freshly uploaded Windows executable. The filename was the first tell: a Chinese-language lure translating roughly to "click here to visit the official Crab website," impersonating a real gaming platform. From the binary alone without sandbox detonation, prior signature, or threat intel feed, we identified it as a Chinese RAT stager. Static analysis and emulation surfaced networking imports, process creation, crypto primitives, and anti-analysis checks including debugger and VM detection. The behavioral chain confirmed it. The stager retrieves a ZIP archive from an AWS S3 bucket, extracts it, and drops a randomized-name second-stage executable, FQDSZYB.exe. String extraction returned the network indicators: the S3 payload URL, and briansclub[.]mx, a domain tied to carding forums, the C2 and update server. The vendors caught up 24 hours later, long enough for the stager to run. Writeup on the Delphos Labs blog. https://lnkd.in/e2BBPKmJ

The difference 24 hours makes is HUGE!

To view or add a comment, sign in

Explore content categories