Threat Actors Leveraging Foxit PDF Reader to Gain System Control and Steal Sensitive Data
## ValleyRAT Campaign Targets Job Seekers
ValleyRAT Campaign Targets Job Seekers
A recent cybersecurity threat, known as the ValleyRAT campaign, has been identified, targeting job seekers by disseminating malware disguised as legitimate recruitment documents. This campaign utilizes email messages that contain fake job offers and company materials to deceive individuals actively searching for employment.
The malware is distributed through compressed archive files labeled with professional-sounding names, such as "Overview_of_Work_Expectations.zip" or "Candidate_Skills_Assessment_Test.rar." When opened, these files install a remote access trojan on the user's system without their knowledge.
The campaign exploits the Foxit PDF Reader by embedding a disguised executable file within the malicious archive. This file appears as the legitimate Foxit application to unsuspecting users, encouraging them to open it without suspicion. The familiar PDF icon misleads users into believing they are accessing a standard document, while in reality, it contains malware designed to compromise their systems.
The attackers employ a technique called DLL side-loading to activate the malicious payload, avoiding detection. A Trend Micro report highlighted a significant increase in ValleyRAT detections in late October, underscoring the campaign's prevalence and sophistication.
This campaign utilizes email messages that contain fake job offers and company materials to deceive individuals actively searching for employment.
The infection process is initiated when a user clicks on the renamed Foxit executable, triggering the automatic loading of a malicious library (msimg32.dll) via Windows' file search mechanism. This action subsequently activates a batch script that extracts a concealed Python environment from innocuous document files. The Python interpreter downloads and executes a malicious script containing shellcode, ultimately deploying the ValleyRAT trojan.
Persistence is achieved by creating registry entries that enable the malware to survive system restarts. Once installed, ValleyRAT grants attackers full control over the compromised machines, allowing them to monitor user activity, steal sensitive data, and extract information from web browsers.
This malware specifically targets password information and login credentials stored in popular browsers, posing a significant threat to personal financial security and identity protection. While job seekers and human resource professionals are primary targets, the campaign continues to evolve to reach broader audiences.
Based on reporting by Cyber Security News.
