ValleyRAT is spreading disguised as adware
概要
Attackers are distributing the ValleyRAT backdoor disguised as legitimate Chinese adware called QN Wallpaper. The malicious installer deploys a modified version of the wallpaper management tool and uses DLL sideloading techniques to execute malicious code under a signed process. ValleyRAT is a sophisticated backdoor capable of keylogging, clipboard monitoring, screenshot capture, and delivering additional modules. The campaign has affected over 1,500 unique users, primarily in China and India, with more than 100,000 detections throughout 2026. Attribution points to the Silver Fox threat group, known for operating ValleyRAT. The attackers disabled Windows Defender, established persistence mechanisms, and implemented process protection techniques including marking processes as critical to trigger system crashes if terminated.
Created: 2026-08-31
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 19.04
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1049 - System Network Connections Discovery
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 17.44
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 11.89
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1560.001 - Archive via Utility
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 4.88
Matched TTPs:
- T1560.001 - Archive via Utility
- T1177 - LSASS Driver
MITREへのリンク →
Score: 21.81
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1556.002 - Password Filter DLL
- T1055.004 - Asynchronous Procedure Call
- T1049 - System Network Connections Discovery
- T1584.002 - DNS Server
MITREへのリンク →
Score: 7.80
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 23.90
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1546.011 - Application Shimming
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1136.003 - Cloud Account
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 6.83
Matched TTPs:
- T1560.001 - Archive via Utility
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 5.51
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 4.34
Matched TTPs:
- T1560.001 - Archive via Utility
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 10.53
Matched TTPs:
- T1560.001 - Archive via Utility
- T1566.001 - Spearphishing Attachment
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 19.08
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1122 - Component Object Model Hijacking
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 5.92
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 8.17
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 8.67
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 18.83
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1027 - Obfuscated Files or Information
- T1574.009 - Path Interception by Unquoted Path
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 14.20
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 38.79
Matched TTPs:
- T1560.001 - Archive via Utility
- T1222.002 - Linux and Mac Permissions
- T1487 - Disk Structure Wipe
- T1139 - Bash History
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
- T1197 - BITS Jobs
- T1055.008 - Ptrace System Calls
- T1546.007 - Netsh Helper DLL
MITREへのリンク →
Score: 25.24
Matched TTPs:
- T1560.001 - Archive via Utility
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1131 - Authentication Package
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 9.58
Matched TTPs:
- T1560.001 - Archive via Utility
- T1592.004 - Client Configurations
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 16.05
Matched TTPs:
- T1560.001 - Archive via Utility
- T1556.002 - Password Filter DLL
- T1546.011 - Application Shimming
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 40.58
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1546.011 - Application Shimming
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1690 - Prevent Command History Logging
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
MITREへのリンク →
Score: 9.36
Matched TTPs:
- T1560.001 - Archive via Utility
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 9.43
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 12.64
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1198 - SIP and Trust Provider Hijacking
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 6.07
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 12.80
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1055.004 - Asynchronous Procedure Call
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 9.65
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 22.87
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1016.002 - Wi-Fi Discovery
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1560.001 - Archive via Utility
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 11.31
Matched TTPs:
- T1560.001 - Archive via Utility
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 10.27
Matched TTPs:
- T1560.001 - Archive via Utility
- T1137.005 - Outlook Rules
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.67
Matched TTPs:
- T1560.001 - Archive via Utility
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 19.38
Matched TTPs:
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1131 - Authentication Package
- T1592.004 - Client Configurations
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 34.83
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1592.004 - Client Configurations
- T1608.005 - Link Target
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 26.97
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
- T1685.004 - Disable or Modify Linux Audit System Log
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1197 - BITS Jobs
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
MITREへのリンク →
Score: 5.78
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 8.70
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.16
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
MITREへのリンク →
Score: 4.16
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 19.94
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1690 - Prevent Command History Logging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 13.58
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1016.002 - Wi-Fi Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 11.06
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1009 - Binary Padding
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 9.26
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.004 - Spearphishing Voice
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1101 - Security Support Provider
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 7.70
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 6.77
Matched TTPs:
- T1099 - Timestomp
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.98
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 9.30
Matched TTPs:
- T1099 - Timestomp
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 11.41
Matched TTPs:
- T1584.008 - Network Devices
- T1009 - Binary Padding
- T1531 - Account Access Removal
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 16.83
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1218.003 - CMSTP
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 8.97
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 14.16
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 35.11
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1049 - System Network Connections Discovery
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1075 - Pass the Hash
MITREへのリンク →
Score: 6.42
Matched TTPs:
- T1484.002 - Trust Modification
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 4.93
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
MITREへのリンク →
Score: 4.20
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
MITREへのリンク →
Score: 21.01
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1566.001 - Spearphishing Attachment
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1592.002 - Software
- T1128 - Netsh Helper DLL
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 10.80
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 21.13
Matched TTPs:
- T1566.001 - Spearphishing Attachment
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 17.66
Matched TTPs:
- T1218.003 - CMSTP
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 8.88
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.87
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 23.99
Matched TTPs:
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 11.02
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 10.61
Matched TTPs:
- T1009 - Binary Padding
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 8.07
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1027 - Obfuscated Files or Information
- T1197 - BITS Jobs
MITREへのリンク →
Score: 5.03
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 9.57
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 6.13
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1690 - Prevent Command History Logging
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.91
Matched TTPs:
- T1177 - LSASS Driver
- T1049 - System Network Connections Discovery
MITREへのリンク →
Score: 13.88
Matched TTPs:
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 7.79
Matched TTPs:
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1531 - Account Access Removal
MITREへのリンク →
Score: 6.88
Matched TTPs:
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1686 - Disable or Modify System Firewall
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1546.008 - Accessibility Features
- T1690 - Prevent Command History Logging
- T1608.005 - Link Target
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1560.001 - Archive via Utility
- T1609 - Container Administration Command
- T1197 - BITS Jobs
- T1546.011 - Application Shimming
MITREへのリンク →
Score: 0.67
Matched TTPs:
- T1139 - Bash History
- T1487 - Disk Structure Wipe
- T1122 - Component Object Model Hijacking
- T1222.002 - Linux and Mac Permissions
- T1608.005 - Link Target
- T1055.008 - Ptrace System Calls
- T1131 - Authentication Package
- T1574.009 - Path Interception by Unquoted Path
- T1546.007 - Netsh Helper DLL
- T1560.001 - Archive via Utility
- T1197 - BITS Jobs
- T1547.011 - Plist Modification
MITREへのリンク →
Score: 0.61
Matched TTPs:
- T1027 - Obfuscated Files or Information
- T1546.008 - Accessibility Features
- T1686.003 - Windows Host Firewall
- T1484.002 - Trust Modification
- T1562.001 - Disable or Modify Tools
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1049 - System Network Connections Discovery
- T1055.004 - Asynchronous Procedure Call
- T1075 - Pass the Hash
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 0.60
Matched TTPs:
- T1027.004 - Compile After Delivery
- T1099 - Timestomp
- T1122 - Component Object Model Hijacking
- T1222.002 - Linux and Mac Permissions
- T1608.005 - Link Target
- T1202 - Indirect Command Execution
- T1592.004 - Client Configurations
- T1584.008 - Network Devices
- T1556.008 - Network Provider DLL
- T1177 - LSASS Driver
- T1547.011 - Plist Modification
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る