typeentityconfidencelowcreated2026-08-13updated2026-08-13malware-familyratpe32plusmingwc2https

ValetGate

Tentative malware-family label for a MinGW-w64 C++ RAT distributed via the gcleaner multi-payload pipeline. Named after the hardcoded user-agent string ValetGate/2.0 (Windows NT 10.0; Kiosk) and the vehicle-themed REST API C2 endpoints (/api/v1/vehicle/entry, /api/v1/vehicle/exit, /api/v1/parking/spot/status).

Overview

Attribute Detail
Platform Windows (PE32+ x64, GUI subsystem)
Compiler MinGW-w64 GCC 15.2.0 (x86_64-posix-seh-rev0)
Size 1,012,944 bytes
Language C++17 with STL (std::vector, std::basic_string)
C2 HTTPS REST to https://pankebab.com
User-Agent ValetGate/2.0 (Windows NT 10.0; Kiosk)

Build / RE

  • Toolchain: MinGW-w64 GCC 15.2.0, GNU ld linker v2.45. No packer, no protector, not stripped. ^[exiftool.json:18] ^[strings.txt:1974]
  • Entropy: Flat (0.44–0.46) across all sections — no encrypted payload sections. ^[binwalk.txt]
  • Imports: WINHTTP.dll (full WinHttp client surface), bcrypt.dll (BCryptOpenAlgorithmProvider), KERNEL32.dll, ADVAPI32.dll, C++ CRT. ^[pefile.txt]
  • Dynamic API loading: GetModuleHandleA("kernelbase.dll") → GetProcAddress("SetThreadDescription"). ^[strings.txt:1772–1773]
  • Anti-analysis: None observed. No debugger checks, VM checks, or timing gates.
  • Code quality: Structured error handling, logging to %TEMP%\agent.log, crash recovery ("CRASH DETECTED — previous instance did not exit cleanly"). Version string "1.0.0". ^[strings.txt:1391–1393]

Deployment / TTPs

  • T1053.005 — schtasks /create /tn WindowsCacheTask /tr "..." /sc ONLOGON /f /rl HIGHEST for logon-triggered persistence. Copies itself to %TEMP%\Microsoft\Windows\Caches\svchost.exe. ^[strings.txt:1433–1440] ^[procedures/schtasks-onlogon-persistence.md]
  • T1027.002 — AES payload decryption via bcrypt.dll (aesEncrypt, "Invalid AES key — using fallback"). ^[strings.txt:1380–1413] ^[techniques/bcrypt-aes-gcm-payload-decryption.md]
  • T1071.001 — HTTPS C2 with REST API masquerade:
    • GET /api/v1/vehicle/entry — beacon/check-in
    • POST /api/v1/vehicle/exit — task results / exfil
    • GET /api/v1/parking/spot/status — poll for new tasks ^[strings.txt:1464–1466] ^[techniques/rest-api-c2-masquerade.md]
  • T1036.004 — User-agent masquerade as ValetGate/2.0 (Windows NT 10.0; Kiosk). ^[techniques/custom-user-agent-masquerade.md]
  • T1036.005 — Process masquerade as svchost.exe in %TEMP%\Microsoft\Windows\Caches\. ^[strings.txt:1440]
  • T1496 — update, update-enc, deploy, deploy-enc, dexec commands for secondary payload delivery. ^[strings.txt:1442–1457]
  • T1490 — Self-update via vg_upd.bat batch script (staged restart with ping delay, move /y, start /b, self-delete). ^[strings.txt:1341–1347]
  • Watchdog — Batch-file watchdog (vg_watchdog.bat) monitors agent PID via tasklist and restarts if the process dies. ^[strings.txt:1395–1408] ^[techniques/watchdog-process-respawning.md]

C2 Protocol Detail

Beacon JSON structure (static reconstruction from strings + decompile):

{
  "agent_id": "<UUID>",
  "hostname": "<hostname>",
  "username": "<username>",
  "os": "windows",
  "ip": "<public_ip>",
  "pid": <pid>,
  "elevated": false,
  "version": "1.0.0",
  "crash_log": "",
  "results": [
    {"task_id": "...", "type": "...", "data": "..."}
  ]
}

^[strings.txt:1367–1379] ^[r2:fcn.14000455a]

Custom request header: X-Vehicle-ID. ^[strings.txt:1385]

Attribution

  • Confidence: low — Single sample (61db1447), static-only (no CAPE detonation). The ValetGate branding could be a custom build, a renamed open-source RAT, or a test binary.
  • Distribution: gcleaner pipeline (OpenCTI label dropped-by-gcleaner). ^[triage.json] ^[entities/gcleaner.md]
  • Builder fingerprint: MinGW-w64 GCC 15.2.0, timestamp 2026-05-27. No PDB path.

Capabilities

  • https-rest-c2-beacon
  • aes-payload-decryption-bcrypt-cng
  • schtasks-onlogon-persistence
  • svchost-process-masquerade
  • self-update-batch-script
  • watchdog-process-respawning
  • tasklist-process-enumeration
  • whoami-system-discovery
  • json-structured-task-results
  • winhttp-download-cap
  • crash-recovery-logging

Related