Fake Huorong Download Site Used to Deploy ValleyRAT Backdoor in Targeted Malware Campaign
An unauthorized group has created a counterfeit website mimicking the Huorong Security antivirus platform to distribute ValleyRAT, a Remote Access Trojan (RAT) based on the Winos4.0 framework. This operation is attributed to the Silver Fox APT group,…
An unauthorized group has created a counterfeit website mimicking the Huorong Security antivirus platform to distribute ValleyRAT, a Remote Access Trojan (RAT) based on the Winos4.0 framework. This operation is attributed to the Silver Fox APT group, known for modifying popular Chinese software to include malware.
Huorong Security, referred to in Chinese as 火绒, is a widely utilized free antivirus solution in mainland China. The attackers registered a domain, huoronga[.]com, which closely resembles the legitimate huorong.cn, differing by only a single character. This tactic, known as typosquatting, targets users who mistype the website address or access it through phishing links.
Malwarebytes analysts have documented the infection process. Upon downloading, the request is discreetly redirected through an intermediary domain, with the final payload being delivered from Cloudflare R2 storage. The file, named BR火绒445[.]zip, uses Huorong's Chinese name to maintain the deception.
The attack leverages a convincing website and installer, counting on users to download the software without suspicion. The lure is particularly effective as it exploits a security product, which might be seen as a trusted source by potential victims.
Once installed, ValleyRAT enables attackers to monitor user activity, exfiltrate sensitive information, and execute commands on the compromised system. The malware captures keystrokes, extracts browser cookies, gathers system information, and injects code into other processes for covert operations. Its modular structure allows additional features to be downloaded as needed, complicating detection and assessment of the full impact.
ValleyRAT modifies Windows Defender settings via PowerShell to exclude its persistence directory ( AppData\Roaming\trvePath ) and primary executable ( WavesSvc64.exe ). It establishes a scheduled task named "Batteries" at C:\Windows\Tasks\Batteries.job to reinitiate the malware upon system startup, connecting to its command and control server at 161.248.87[.]250 over TCP port 443.
The malware obscures its presence by deleting and rewriting its core files to evade signature-based detection. Before full deployment, it checks for debugging tools and virtualized environments. Configuration data, including the encoded C2 domain yandibaiji0203[.]com, is stored in the registry under HKCU\SOFTWARE\IpDates_info . Organizations are advised to block outbound connections to 161.248.87[.]250, audit unauthorized Defender exclusions, and monitor for the "Batteries" task and %APPDATA%\trvePath\ directory as infection indicators.
Type Indicator
Fake Domain huoronga[.]com
Fake Domain huorongcn[.]com
Fake Domain huorongh[.]com
This operation is attributed to the Silver Fox APT group, known for modifying popular Chinese software to include malware.
Fake Domain huorongpc[.]com
Fake Domain huorongs[.]com
Redirect Domain hndqiuebgibuiwqdhr[.]cyou
Payload Host pub-b7ce0512b9744e2db68f993e355a03f9.r2[.]dev
C2 IP 161.248.87[.]250 (TCP 443)
Encoded C2 Domain yandibaiji0203[.]com
SHA-256 — NSIS Installer 72889737c11c36e3ecd77bf6023ec6f2e31aecbc441d0bdf312c5762d073b1f4
SHA-256 — WavesSvc64.exe db8cbf938da72be4d1a774836b2b5eb107c6b54defe0ae631ddc43de0bda8a7e
SHA-256 — DuiLib_u.dll d0ac4eb544bc848c6eed4ef4617b13f9ef259054fe9e35d9df02267d5a1c26b2
SHA-256 — WinosStager DLL #1 07aaaa2d3f2e52849906ec0073b61e451e0025ef2523dafbd6ae85ddfa587b4d
SHA-256 — WinosStager DLL #2 66e324ea04c4abbad6db4f638b07e2e560613e481ff588e0148e33e23a5052a9
SHA-256 — WinosStager DLL #3 47df12b0b01ddca9eb116127bf84f63eb31e80cec33e4e6042dff1447de8f45f
Scheduled Task C:\Windows\Tasks\Batteries.job
Persistence Directory %APPDATA%\trvePath\
Registry Key HKCU\SOFTWARE\IpDates_info
Registry Key HKCU\Console\0\451b464b7a6c2ced348c1866b59c362e
Log File C:\ProgramData\DisplaySessionContainers.log
Based on reporting by Cyber Security News.
