Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fake Huorong Download Site Used to Deploy ValleyRAT Backdoor in Targeted Malware Campaign

An unauthorized group has created a counterfeit website mimicking the Huorong Security antivirus platform to distribute ValleyRAT, a Remote Access Trojan (RAT) based on the Winos4.0 framework. This operation is attributed to the Silver Fox APT group,…

An unauthorized group has created a counterfeit website mimicking the Huorong Security antivirus platform to distribute ValleyRAT, a Remote Access Trojan (RAT) based on the Winos4.0 framework. This operation is attributed to the Silver Fox APT group, known for modifying popular Chinese software to include malware.

Huorong Security, referred to in Chinese as 火绒, is a widely utilized free antivirus solution in mainland China. The attackers registered a domain, huoronga[.]com, which closely resembles the legitimate huorong.cn, differing by only a single character. This tactic, known as typosquatting, targets users who mistype the website address or access it through phishing links.

Malwarebytes analysts have documented the infection process. Upon downloading, the request is discreetly redirected through an intermediary domain, with the final payload being delivered from Cloudflare R2 storage. The file, named BR火绒445[.]zip, uses Huorong's Chinese name to maintain the deception.

The attack leverages a convincing website and installer, counting on users to download the software without suspicion. The lure is particularly effective as it exploits a security product, which might be seen as a trusted source by potential victims.

Once installed, ValleyRAT enables attackers to monitor user activity, exfiltrate sensitive information, and execute commands on the compromised system. The malware captures keystrokes, extracts browser cookies, gathers system information, and injects code into other processes for covert operations. Its modular structure allows additional features to be downloaded as needed, complicating detection and assessment of the full impact.

ValleyRAT modifies Windows Defender settings via PowerShell to exclude its persistence directory ( AppData\Roaming\trvePath ) and primary executable ( WavesSvc64.exe ). It establishes a scheduled task named "Batteries" at C:\Windows\Tasks\Batteries.job to reinitiate the malware upon system startup, connecting to its command and control server at 161.248.87[.]250 over TCP port 443.

The malware obscures its presence by deleting and rewriting its core files to evade signature-based detection. Before full deployment, it checks for debugging tools and virtualized environments. Configuration data, including the encoded C2 domain yandibaiji0203[.]com, is stored in the registry under HKCU\SOFTWARE\IpDates_info . Organizations are advised to block outbound connections to 161.248.87[.]250, audit unauthorized Defender exclusions, and monitor for the "Batteries" task and %APPDATA%\trvePath\ directory as infection indicators.

Type Indicator

Fake Domain huoronga[.]com

Fake Domain huorongcn[.]com

Fake Domain huorongh[.]com

This operation is attributed to the Silver Fox APT group, known for modifying popular Chinese software to include malware.
Zachary Burns · Thehackingpost

Fake Domain huorongpc[.]com

Fake Domain huorongs[.]com

Redirect Domain hndqiuebgibuiwqdhr[.]cyou

Payload Host pub-b7ce0512b9744e2db68f993e355a03f9.r2[.]dev

C2 IP 161.248.87[.]250 (TCP 443)

Encoded C2 Domain yandibaiji0203[.]com

SHA-256 — NSIS Installer 72889737c11c36e3ecd77bf6023ec6f2e31aecbc441d0bdf312c5762d073b1f4

SHA-256 — WavesSvc64.exe db8cbf938da72be4d1a774836b2b5eb107c6b54defe0ae631ddc43de0bda8a7e

Advertisement

SHA-256 — DuiLib_u.dll d0ac4eb544bc848c6eed4ef4617b13f9ef259054fe9e35d9df02267d5a1c26b2

SHA-256 — WinosStager DLL #1 07aaaa2d3f2e52849906ec0073b61e451e0025ef2523dafbd6ae85ddfa587b4d

SHA-256 — WinosStager DLL #2 66e324ea04c4abbad6db4f638b07e2e560613e481ff588e0148e33e23a5052a9

SHA-256 — WinosStager DLL #3 47df12b0b01ddca9eb116127bf84f63eb31e80cec33e4e6042dff1447de8f45f

Scheduled Task C:\Windows\Tasks\Batteries.job

Persistence Directory %APPDATA%\trvePath\

Registry Key HKCU\SOFTWARE\IpDates_info

Registry Key HKCU\Console\0\451b464b7a6c2ced348c1866b59c362e

Log File C:\ProgramData\DisplaySessionContainers.log

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories