Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit Telegram, WinSCP, Chrome, and Teams to Deliver ValleyRat Malware

Researchers have uncovered a sophisticated malware campaign where threat actors weaponize trojanized installers for popular productivity applications to deploy ValleyRat, a persistent remote access tool. The operation demonstrates advanced evasion…

Researchers have uncovered a sophisticated malware campaign where threat actors weaponize trojanized installers for popular productivity applications to deploy ValleyRat, a persistent remote access tool. The operation demonstrates advanced evasion techniques, including kernel-level driver abuse, endpoint security tampering, and multi-stage obfuscation designed to evade detection and establish long-term system compromise. The campaign has been attributed to Silver Fox, a China-aligned advanced persistent threat (APT) group active since at least 2022. The threat actors repurpose legitimate installer files for Telegram, WinSCP, Google Chrome, and Microsoft Teams applications that users regularly download and trust. Upon execution, victims observe a standard installation interface while malware silently stages payloads, deploys kernel drivers, turns off security defenses, and launches a ValleyRat beacon that grants adversaries persistent remote access. The Infection Chain The attack unfolds through a meticulously coordinated sequence. Initial compromise occurs when victims execute a trojanized Telegram installer (tg.exe) distributed via spear-phishing and malvertising campaigns. Silver Fox Telegram installer infection chain. The binary, masquerading as Telegram Desktop version 6.0.2, displays a legitimate user interface while immediately executing malicious post-exploitation activities. Upon launch, the installer creates the staging directory C:\ProgramData\WindowsData\ and deploys a renamed 7-Zip binary alongside a password-protected archive disguised as main.xml. Telegram UI showing Version 6.0.2. Critically, the installer then uses PowerShell to add a Microsoft Defender exclusion for the entire C: drive a dangerous configuration change that disables antivirus protection system-wide. The archive is subsequently extracted using the command-line password htLcENyRFYwXsHFnUnqK, yielding a second-stage orchestrator binary named men.exe. The men.exe component orchestrates subsequent infection stages. It enumerates running processes to identify security software, including Microsoft Defender and Chinese security products such as ZhuDongFangYu and 360tray indicating geographic targeting. The orchestrator then deploys additional password-protected archives containing drivers, privilege escalation tools, persistence mechanisms, and the ValleyRat payload to %PUBLIC%\Documents\WindowsData\. Defense Evasion and Persistence The campaign employs multiple overlapping evasion techniques. A UAC bypass utility leverages the ICMLuaUtil elevated COM interface to escalate privileges. Two kernel-mode drivers rwdriver.sys and the vulnerable but signed NSecKrnl64.sys operate at ring 0 to weaken endpoint protection. The custom driver circumvents user-mode EDR hooks, interferes with logging mechanisms by overloading event forwarding pipelines, and repeatedly terminates security solution processes. A legitimately signed executable (NtHandleCallback.exe) performs DLL sideloading to execute the malicious log.dll beacon. Persistence is maintained through a scheduled task named WindowsPowerShell.WbemScripting.SWbemLocator deliberately mimicking legitimate Windows components. Persistence detection based on a one letter script file name. The task executes an encoded VBScript (X.vbe) at logon, which triggers both the vulnerable driver loader and the ValleyRat beacon. Access control lists are modified to prevent even administrators from removing the staging directory, complicating remediation efforts. Detection and Response Despite its sophistication, the campaign presents multiple reliable detection opportunities. File system monitoring of C:\ProgramData\WindowsData\ and %PUBLIC%\Documents\WindowsData\ identifies anomalous staging activities. THOR detects these drivers via YARA signatures (for example, EXT_Winnti_Rootkit in related tooling), driver location checks and generic service analysis. Driver registration showing up as service in the Registry. Microsoft Defender Operational event ID 5007 captures suspicious exclusion modifications. Process creation logs reveal password-protected archive extraction commands and UAC bypass CLSID invocations. Service creation events expose kernel driver registration from user-writable directories. Organizations should implement strict application control policies, restrict local administrator rights, monitor process execution from public user directories, and deploy comprehensive endpoint detection and response (EDR) solutions capable of detecting kernel-mode driver abuse and DLL sideloading techniques. DNS logging and process-level C2 detection provide additional visibility into command-and-control communications used by the ValleyRat beacon. Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

The campaign has been attributed to Silver Fox, a China-aligned advanced persistent threat (APT) group active since at least 2022.
Katherine Doyle · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories