Find notable cyber news and cases, enriched with sources, timelines, and signals.

ValleyRAT malicious installer activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has affected China-based multinational operations and Chinese-speaking users across multiple industries. Once launched, the payload sets persistence, weakens security protections, and establishes C2, raising the risk of follow-on intrusion and device compromise.

Related Happenings

Silver Fox bogus software-download websites campaign

Campaign
H score38 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

How related: An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

About this happening: An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based...

HoneyMyte PlugX campaign targeting Myanmar

Campaign
H score32 First: 14.08.2026 16:08 Last: 14.08.2026 16:08 Sources 1

About this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...

Mastra @mastra/* npm packages hit by network compromise

Incident
H score47 First: 17.06.2026 10:38 Last: 17.06.2026 10:38 Sources 1

About this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...

Latest development: 20.06.2026 17:09

Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Timeline

  1. 02.09.2026 19:41 2 articles · 2h ago

    Bogus vendor download sites deliver malicious Windows installers

    Initial Disclosure

    Microsoft reported an active malware campaign using high-fidelity counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers to users seeking popular software. The activity has compromised organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education, primarily affecting China-based operations of multinational organizations and Chinese-speaking users; observed chains include wrapper installers and a second path that uses the trusted Windows Installer service (msiexec.exe), with the payload setting persistence, creating Microsoft Defender exclusions via PowerShell, deleting volume shadow copies, tampering with Windows Update, and establishing C2 over non-standard ports.

    Show sources