Security researchers at Intezer are warning of new cyberattacks that have targeted Chinese-speaking regions, such as Hong Kong, Taiwan, and mainland China, with a malware called ValleyRAT (via the multi-stage loader PNGPlug).

The attacks begin with a phishing page that encourages victims to download a malicious Microsoft Installer (MSI) package, disguised as legitimate software.
Once executed, the installer deploys a benign application, while at the same time secretly extracting an encrypted file containing the malware.
See also: Bitter Group targets defense sector with WmRAT and MiyaRAT malware
“The MSI package uses the CustomAction feature of Windows Installer, thereby executing malicious code, including an embedded malicious DLL that decrypts the file (all.zip) using a hardcoded password “hello202411” to extract the core malware components,” said security researcher Nicole Fishbein.
The malware components include a DLL file (“libcef.dll”), a legitimate application (“down.exe”), which hides the malicious activities , and two payload files presented as PNG images (“aut.png” and “view.png”).
The main goal of the DLL loader, PNGPlug, is to prepare the environment for the execution of the main malware, ValleyRAT, by injecting “aut.png” and “view.png” into memory.
See also: HiatusRAT targets webcams and DVRs
ValleyRAT is a remote access trojan (RAT) that provides unauthorized access and control over infected machines. Recent versions have features to take screenshots and clean up Windows event logs.
It is estimated that the ValleyRAT malware is associated with a threat group called Silver Fox.

Protection against RAT malware
The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.
Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.
See also: RAT Attacks: What They Are and How You Can Protect Yourself
You should also be careful with emails and messages you receive. Many RAT malware (ValleyRAT malware) are spread through phishing attacks, so avoid opening attachments or clicking on links from unknown sources.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.
Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.
Source: thehackernews.com
