Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ValleyRAT Malware Uses Stealthy Driver Install to Bypass Windows 11 Protections

ValleyRAT, also referred to as Winos or Winos4.0, is a sophisticated backdoor threat targeting organizations globally. This modular malware family poses a notable risk to Windows systems, specifically those running Windows 11 with the latest security…

ValleyRAT, also referred to as Winos or Winos4.0, is a sophisticated backdoor threat targeting organizations globally. This modular malware family poses a notable risk to Windows systems, specifically those running Windows 11 with the latest security updates.

The public leak of the ValleyRAT builder and its development framework has expanded its accessibility beyond its initial user base. This malware employs attack vectors at multiple system levels, functioning as a comprehensive remote access trojan capable of deploying various plugins to compromise victim systems.

Initial infections typically utilize first-stage plugins such as the Online Module or Login Module, which serve as beacons to the command-and-control server. These plugins retrieve and load additional specialized plugins, progressively expanding the operator's foothold in compromised networks.

Attackers selectively deploy more advanced components to certain victims, demonstrating a sophisticated understanding of Windows internals. Check Point security analysts discovered that ValleyRAT's developers possess advanced knowledge of kernel-mode and user-mode mechanisms, indicating a coordinated development team.

ValleyRAT, also referred to as Winos or Winos4.0, is a sophisticated backdoor threat targeting organizations globally.
Sarah Dawson · Thehackingpost

A critical component of ValleyRAT is its embedded kernel-mode rootkit driver, found within the Driver Plugin. This rootkit retains valid signatures, allowing it to bypass modern protection features on fully updated Windows 11 systems.

Approximately 85 percent of detected ValleyRAT samples were observed in the last six months, correlating with the builder's public release. The rootkit facilitates stealthy driver installations and user-mode shellcode injection via asynchronous procedure calls.

ValleyRAT aggressively deletes antivirus and endpoint detection and response drivers from compromised systems, particularly targeting security solutions from vendors such as Qihoo 360, Huorong Security, Tencent, and Kingsoft Corporation. This removal creates an unsecured environment for attackers.

Advertisement

The public availability of the builder and development framework complicates attribution and allows actors to compile, modify, and deploy ValleyRAT independently. Organizations must implement robust detection systems and maintain updated security measures to counter this evolving threat.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories