typeentityconfidencelowcreated2026-06-14updated2026-09-06malware-familyratdotnetc2persistence

ValleyRAT

A tentative malware-family label from OpenCTI and MalwareBazaar co-applied to a cluster of samples that share the silverfox tag. The relationship between ValleyRAT and SilverFox is unconfirmed — they may be the same family under different naming conventions, a fork, or distinct families sharing infrastructure or detection artefacts.

Overview

Attribute Detail
Platform Windows (PE32/PE32+ x86/x64)
Build variants Rust dropper (SilverFox ed1a...) — LZSS + stream cipher, process hollowing ^[silverfox] <br> C stub (SilverFox 82d4...) — FNV-1a API resolution, XOR thunk ^[silverfox] <br> .NET Native AOT (fbc07658) — PublishAOT console binary, 10 MB, 52pojie build provenance <br> Inno Setup dropper (480c184e) — Delphi 36.0, encrypted 4.2 MB overlay, "PrinterDoctor" masquerade, Qihoo 360 expired signing
Labels valleyrat, silverfox (co-tagged on some variants)

The .NET Native AOT variant (fbc07658) diverges radically from the established SilverFox cluster. It is compiled with ILC ahead-of-time compilation from a net10.0 project named Update, built on a workstation associated with the Chinese reverse-engineering forum 52pojie. It lacks LZSS decompression, process hollowing, XOR-thunk dispatch, and embedded payload artefacts observed in all reported SilverFox builds. Whether this represents a new ValleyRAT build pipeline or a mislabeled sample is undetermined.

Capabilities

  • dotnet-native-aot-self-contained-deployment
  • async-http-c2-loop
  • brotli-compression-embedded-apis
  • registry-key-manipulation
  • process-creation-win32
  • virtualalloc-virtualprotect-memory-management
  • bcrypt-crypt32-cryptography
  • winhttp-socket-networking
  • async-await-state-machine-obfuscation
  • version-info-masquerade-update
  • inno-setup-delphi-encrypted-overlay-dropper
  • expired-authenticode-signing-trust-abuse

Build artefacts

Sample Build Size Key features
fbc07658...abce15 .NET Native AOT (ILC), MSVC 14.51, net10.0 10 MB 52pojie PDB, Brotli exports, System.Net.Http, no C2 strings
480c184e...9472503 Inno Setup 7.0.0.1, Delphi 36.0 5.3 MB Encrypted 4.2 MB overlay, "PrinterDoctor" masquerade, expired Qihoo 360 Authenticode

Notable Analyses

  • fbc07658954f87579d615e72f76335f6fae5cec34a283535a37f72d6a4abce15 — .NET Native AOT console binary, Update.dll masquerade, 52pojie build provenance, full BCL networking/crypto stack, static-only (CAPE skipped).
  • 480c184e69a19d4f3bb595324d618eead8f6fcc5176f1ebc5e44ee1389472503 — Inno Setup 7.0.0.1 "PrinterDoctor" dropper, encrypted 4.2 MB overlay, expired Qihoo 360 Authenticode, static-only (CAPE skipped).

Related