Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Operation Silk Lure: Weaponizing Windows Scheduled Tasks for ValleyRAT Delivery

A targeted cyber-espionage campaign has been identified, exploiting Windows Scheduled Tasks and DLL side-loading to deploy the ValleyRAT backdoor. This operation primarily affects Chinese FinTech and cryptocurrency firms through a series of sophisticated…

A targeted cyber-espionage campaign has been identified, exploiting Windows Scheduled Tasks and DLL side-loading to deploy the ValleyRAT backdoor. This operation primarily affects Chinese FinTech and cryptocurrency firms through a series of sophisticated tactics.

The campaign employs spear-phishing emails, weaponized Windows shortcuts, and a persistent task scheduler mechanism to deliver a multi-stage malware payload. These emails, crafted to appear as job applications, target HR and technical teams. Each email includes a malicious .LNK shortcut embedded in a seemingly legitimate résumé PDF. Seqrite Lab researchers have uncovered the operation, which reveals its command and control (C2) server at 206.119.175.16 and initiates the ValleyRAT backdoor.

The decoy résumé is written in Simplified Chinese, presenting a profile for 李汉兵 (Li Hanbing), a senior full-stack engineer. This detailed profile includes credentials such as a degree from South China Agricultural University and work history at notable tech firms, enhancing its authenticity.

Upon execution of the .LNK file, a PowerShell one-liner is triggered, reaching out to pan.tenire.com in the United States to download key artifacts such as keytool.exe , CreateHiddenTask.vbs , jli.dll , and a decoy PDF. These files are placed in the %APPDATA%\Security directory, initiating the next stage of the attack.

A targeted cyber-espionage campaign has been identified, exploiting Windows Scheduled Tasks and DLL side-loading to deploy the ValleyRAT backdoor.
Joseph Cain · Thehackingpost

Persistence is maintained through a VBScript ( CreateHiddenTask.vbs ) that registers a daily scheduled task named “Security.” This task executes keytool.exe at 8:00 AM, appearing as a Microsoft-signed process. The script self-deletes after registering the task to remove forensic evidence.

At runtime, keytool.exe side-loads jli.dll , decrypting an RC4-encrypted payload with a fixed key in memory, executing it directly without disk writes.

The second-stage payload, ValleyRAT, conducts extensive reconnaissance, collecting system and network information, and executes measures to evade virtual environments and disable antivirus software.

Advertisement

Operation Silk Lure employs advanced techniques to infiltrate targeted enterprises. Organizations should monitor for indicators such as DNS queries to pan.tenire.com , scheduled tasks named “Security,” and unusual PowerShell activity. Implementing application whitelisting, monitoring unexpected scheduled tasks, and blocking access to identified C2 infrastructure can help mitigate these threats.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories