Fake Huorong security site infects users with ValleyRAT

Feb. 23, 2026, 10:51 p.m.

Description

A sophisticated campaign by the Silver Fox APT group has been discovered using a fake version of the popular Chinese antivirus Huorong Security to distribute ValleyRAT, a Remote Access Trojan. The attackers created a convincing lookalike website with a typosquatted domain to trick users into downloading a malicious installer. The malware uses DLL sideloading techniques to deploy a full-featured backdoor with advanced stealth capabilities. It establishes persistence through scheduled tasks, disables Windows Defender, and employs various evasion tactics. Once installed, ValleyRAT provides attackers with extensive control over the victim's system, including keylogging, process injection, and credential theft. The campaign primarily targets Chinese-language systems but may be spreading to other threat actors due to the public leak of the ValleyRAT builder.

Date

  • Created: Feb. 23, 2026, 3 p.m.
  • Published: Feb. 23, 2026, 3 p.m.
  • Modified: Feb. 23, 2026, 10:51 p.m.

Indicators

  • 07aaaa2d3f2e52849906ec0073b61e451e0025ef2523dafbd6ae85ddfa587b4d
  • 72889737c11c36e3ecd77bf6023ec6f2e31aecbc441d0bdf312c5762d073b1f4
  • d0ac4eb544bc848c6eed4ef4617b13f9ef259054fe9e35d9df02267d5a1c26b2
  • 66e324ea04c4abbad6db4f638b07e2e560613e481ff588e0148e33e23a5052a9
  • 47df12b0b01ddca9eb116127bf84f63eb31e80cec33e4e6042dff1447de8f45f
  • db8cbf938da72be4d1a774836b2b5eb107c6b54defe0ae631ddc43de0bda8a7e
  • 161.248.87.250

Attack Patterns

Additional Informations

  • yandibaiji0203.com
  • hndqiuebgibuiwqdhr.cyou
  • huoronga.com
  • huorongh.com
  • huorongpc.com
  • huorongcn.com
  • huorongs.com
  • China