ValleyRAT masquerading as adware

Kaspersky Securelist Version 1 original current

Imported from official source

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

This version

Version
1 of 1
Recorded
September 20, 2026 19:52
Change
Initial
Content hash
673134713efc6522fb320ad63b03aaf3
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.