ValleyRAT malicious installer activity
Malware Activity
Summary
Hide ▲
Show ▼
ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has affected China-based multinational operations and Chinese-speaking users across multiple industries. Once launched, the payload sets persistence, weakens security protections, and establishes C2, raising the risk of follow-on intrusion and device compromise.
Related Happenings
Silver Fox bogus software-download websites campaign
Campaign
H score38
First: 02.09.2026 19:41
Last: 02.09.2026 19:41
Sources 1
How related:
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
About this happening:
An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based...
Silver Fox bogus software-download websites campaign
CampaignHow related: An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
About this happening: An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based...
HoneyMyte PlugX campaign targeting Myanmar
Campaign
H score32
First: 14.08.2026 16:08
Last: 14.08.2026 16:08
Sources 1
About this happening:
The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
HoneyMyte PlugX campaign targeting Myanmar
CampaignAbout this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...
Mastra @mastra/* npm packages hit by network compromise
Incident
H score47
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Mastra @mastra/* npm packages hit by network compromise
IncidentAbout this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Latest development: 20.06.2026 17:09
Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Timeline
-
02.09.2026 19:41 2 articles · 2h ago
Bogus vendor download sites deliver malicious Windows installers
Initial DisclosureMicrosoft reported an active malware campaign using high-fidelity counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers to users seeking popular software. The activity has compromised organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education, primarily affecting China-based operations of multinational organizations and Chinese-speaking users; observed chains include wrapper installers and a second path that uses the trusted Windows Installer service (msiexec.exe), with the payload setting persistence, creating Microsoft Defender exclusions via PowerShell, deleting volume shadow copies, tampering with Windows Update, and establishing C2 over non-standard ports.
Show sources
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender — thehackernews.com — 02.09.2026 19:41
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender — thehackernews.com — 02.09.2026 19:41