Attackers are gaming search results so that people looking for the KakaoTalk messenger download a booby-trapped installer. AhnLab says the malware has kept changing shape, most recently hiding its code inside a PNG image.

Attackers are gaming search results so that people looking for the KakaoTalk messenger download a booby-trapped installer. AhnLab says the malware has kept changing shape, most recently hiding its code inside a PNG image.
Fake Razer and Edge download sites rebuild the installer per request - hash blocking is useless. https://intel.threadlinqs.com/threat/TL-2026-2773 #ThreatIntel #ValleyRAT #Ghost #Silver
-> 39140128092026.824.img -> pdfcorE8.dll, 他正規ファイルの悪用
www.virustotal.com/gui/file/952...
tria.ge/260928-g9w2n...
app.any.run/tasks/6d2ffd...
マルウェア #ValleyRAT
■C2
45.202.1[.]249:913
45.202.1[.]249:912
■ダウンロード
PDF_資金移動完了証明書.ZIP -> hdp.dll, PDF_資金移動完了証明書.exe, 他.txtファイル
www.virustotal.com/gui/file/4df...
tria.ge/260925-mzjw8...
app.any.run/tasks/be21fb...
マルウェア #ValleyRAT
■通信先
hxxp[:]//apm.hexin[.]cn/trace?appId=4&isZip=0
(58.220.49[.]156:80)
■C2
103.42.30[.]245:7811
103.42.30[.]245:7800
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/09/08(火)
■件名
令和8年度 第3四半期 税務関連資料および確認清单(チェックリスト)のご送付 [受付番号:2609018653]
■添付ファイル
税務報告書[.]zip -> 税務報告書.img -> out.iso -> FileReportEx.dll, 他.dat,.cnf,正規ファイルなど
www.virustotal.com/gui/file/ad9...
tria.ge/260908-b22pa...
マルウェア #ValleyRAT
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/09/04(金)
■件名
電子インボイス発行完了のお知らせ
■添付ファイル
RKM-20260904-1514.7z -> Open_to_view_f4d1.img -> winhttp.dll, Open_to_view.exe
www.virustotal.com/gui/file/bf1...
tria.ge/260907-gsq43...
マルウェア #ValleyRAT
■C2
202.146.222[.]95:443
Silver Fox fake software installers impersonate Razer and Edge to disable Windows Defender and deploy malware. See how the campaign works.
#SilverFox #FakeInstallers #WindowsDefender #Malware #Yinhu #ValleyRAT #ThreatIntel #Infosec