{"id":11696,"date":"2026-03-25T13:09:26","date_gmt":"2026-03-25T13:09:26","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11696"},"modified":"2026-03-25T13:09:27","modified_gmt":"2026-03-25T13:09:27","slug":"valleyrat-unleashed-a-deep-dive-into-its-modern-arsenal-and-tactics","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/valleyrat-unleashed-a-deep-dive-into-its-modern-arsenal-and-tactics\/","title":{"rendered":"ValleyRAT Unleashed: A Deep Dive into its Modern Arsenal and Tactics"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">ValleyRAT Unleashed: A Deep Dive into its Modern Arsenal and Tactics<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reported cases increased sharply from late 2024 to 2025. We observed attacks by SilverFox primarily targeting Chinese-speaking individuals in Southeast Asia and East Asia, abusing multiple legitimate software programs, including fake LINE installers, to spread ValleyRAT. Further investigation revealed that the attacks were not limited to LINE and that a variety of software programs were being exploited.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ValleyRAT was thought to be original malware exclusive to SilverFox, but source code and a builder are in circulation, and the builder was released at least as early as February 2023. As a result, as of July 2025, attacks using various execution chains are being carried out using this malware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ValleyRAT&#8217;s attack chain is often distributed as a fake software installer using SEO poisoning or phishing emails. However, espionage-like attacks have also been reported, such as spear-phishing emails targeting businesses, such as government agency communications or invoices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ValleyRAT uses a wide variety of tools and techniques. In this presentation, we will organize attacks using ValleyRAT observed since 2025 by the following execution chain:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8211; DLL side-load fake installer<br>&#8211; Payload embedded in the image (a.k.a. PNGPlug)<br>&#8211; Go-Lang<br>&#8211; APT-like Masquerading Loader<br>&#8211; Donuts<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During our investigation, we discovered new patterns using WinRAR SFX and Go language loaders. We also found cases where the same export name as MustangPanda was used in DLL side-loading in ValleyRAT&#8217;s execution chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For each execution chain, we will analyze the targets, TTPs, and C2 infrastructure, and propose a classification of ValleyRAT&#8217;s attack campaigns. Finally, we will share hunting techniques for ValleyRAT (Winos 4.0).<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Hiromu-Kubiura.png\" alt=\"\" class=\"wp-image-11697\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Hiromu-Kubiura.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Hiromu-Kubiura-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Hiromu-Kubiura-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Hiromu-Kubiura-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong>Hiromu Kubiura &#8211; LY Corporation<\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At LY Corporation, I conduct threat intelligence focused on malware analysis and phishing countermeasures. I have presented at Black Hat USA Arsenal and BSides Tokyo.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/dummy-image.jpg\" alt=\"\" class=\"wp-image-11698\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/dummy-image.jpg 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/dummy-image-300x300.jpg 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/dummy-image-150x150.jpg 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/dummy-image-200x200.jpg 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong>Ryonosuke Kawakami &#8211; Cyber Defense Institute, Inc<\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ryonosuke Kawakami is a threat researcher at Cyber Defense Institute with deep expertise in malware analysis and reverse engineering. His work focuses on tracking APT campaigns, reverse engineering malware, and conducting memory forensics. He turns low-level findings into action\u2014deobfuscating code, profiling C2, and informing APT attribution.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Shota-Nakajima.png\" alt=\"\" class=\"wp-image-11699\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Shota-Nakajima.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Shota-Nakajima-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Shota-Nakajima-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Shota-Nakajima-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong><strong>Shota Nakajima &#8211; Cyber Defense Institute, Inc<\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Shota Nakajima is a Tech Lead of Threat Intelligence at the Cyber Defense Institute, Inc. He specializes in malware analysis, with deep expertise in reverse engineering. In the field of threat intelligence, he actively tracks the latest Advanced Persistent Threats (APTs) and has presented his extensive research at numerous international conferences, including JSAC, VB, HITCON, AVAR, CODE BLUE and Black Hat Arsenal. Leveraging his specialized knowledge, he is also dedicated to developing practical and effective threat intelligence products.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back ValleyRAT Unleashed: A Deep Dive into its Modern Arsenal and Tactics Reported cases increased sharply from late 2024 to 2025. We observed attacks by SilverFox primarily targeting Chinese-speaking individuals in Southeast Asia and East Asia, abusing multiple legitimate software programs, including fake LINE installers, to spread ValleyRAT. Further investigation revealed<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/valleyrat-unleashed-a-deep-dive-into-its-modern-arsenal-and-tactics\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11696","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11696","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11696"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11696\/revisions"}],"predecessor-version":[{"id":11700,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11696\/revisions\/11700"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11696"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}