ValleyRAT masquerading as adware

Executive Summary

Threat actors distribute the ValleyRAT backdoor disguised as adware. The analysis covers the infection chain from the malicious installer to the final payload, detailing how the installer spreads and how the backdoor operates.


Intelligence Metadata - Source Publisher: Securelist - Published Date: 2026-08-31T10:00:21+00:00 - Category: malware

Original Description: Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

"Some people thrive on huge, dramatic change. Some people prefer the slow and steady route. Do what's right for you."

— Julie Morgenstern
Source: Securelist