PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers

Post by Shane1145 »

Cybersecurity researchers are calling attention to a series of cyber attacks that have targeted Chinese-speaking regions like Hong Kong, Taiwan, and Mainland China with a known malware called ValleyRAT.

The attacks leverage a multi-stage loader dubbed PNGPlug to deliver the ValleyRAT payload, Intezer said in a technical report published last week.

The infection chain commences with a phishing page that's designed to encourage victims to download a malicious Microsoft Installer (MSI) package disguised as legitimate software.

https://thehackernews.com/2025/01/pngpl ... eyrat.html
Post Reply