typetechniqueconfidencehighcreated2026-08-13updated2026-08-13command-and-controlmasqueradeuser-agentdefense-evasion

Custom User-Agent Masquerade

Malware sets an HTTP User-Agent header that mimics a legitimate browser, application, or platform — but with a custom or unusual product name that can serve as a family fingerprint.

Mechanism

Via WinHttpOpen or InternetOpenA, the malware passes a hardcoded User-Agent string. The string may be:

  • A near-copy of a real browser UA with one altered token (e.g., Chrome/128.0.0.0 Safari/537.36 → Chrome/128.0.0.0 Kiosk/1.0).
  • A completely synthetic UA that follows browser UA syntax but uses a unique product name.

Detection / Fingerprint

  • Correlation of unusual product tokens with suspicious hostnames.
  • User-Agent + X-* custom header clustering across samples.
  • EDR / proxy logs: WinHttpOpen with non-standard UAs from unsigned binaries.

Observed In

  • valetgate — ValetGate/2.0 (Windows NT 10.0; Kiosk). ^[/intel/analyses/61db1447817fd3b40db67ed261238e15f6338dc642a7a5a4bbf0c0ea5248594e.html]
  • silverfox — Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/128.0.0.0. ^[entities/silverfox.md]