National Cyber Warfare Foundation (NCWF)

ValleyRAT Masquerades as LINE Installer to Target Users and Harvest Login Credentials


0 user ratings
2026-02-04 08:05:29
milo
Red Team (CNA)

A malware campaign where cybercriminals distribute a fake LINE messenger installer that secretly deploys the ValleyRAT malware to steal credentials and evade detection. Since early 2025, threat actors have increasingly used fraudulent software installers to deliver malware. This campaign shares techniques with previously discovered LetsVPN-themed attacks, including task-scheduler persistence, PowerShell-based evasion, and C2 communications via Hong Kong servers. Cybereason GSOC performed […]


The post ValleyRAT Masquerades as LINE Installer to Target Users and Harvest Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/valleyrat-malware-3/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.