Weaponized Microsoft Office Document Delivers ValleyRAT Malware to Windows Systems

Researchers at ANY.RUN have identified a complex cyberattack aimed specifically at Chinese-speaking individuals. This attack disseminates a multi-stage malware known as ValleyRAT, which is engineered to penetrate systems and establish persistent backdoors, enabling attackers to monitor and control the compromised devices remotely.

Once ValleyRAT is active, it deploys additional components to broaden its attack capabilities, which may include data theft, ransomware deployment, or the creation of botnets. This malware presents a serious risk to Chinese-speaking users and organizations, underscoring the critical need for strong cybersecurity defenses and heightened awareness of such sophisticated threats.

A cyber campaign targeting this demographic has been discovered, involving emails with malicious links leading to compressed executables containing the ValleyRAT malware. This advanced threat is adept at avoiding detection by executing directly in system memory.

ValleyRAT’s functionality includes persistence and privilege escalation, allowing it to secure its position within compromised systems and access sensitive information. First detected in June 2024, this campaign has continued to evolve, using more advanced techniques to avoid detection and increase its effectiveness.

The attack sequence begins with a malicious executable masquerading as a legitimate application. Once run, it drops a decoy document and loads shellcode to establish a connection with a command-and-control (C2) server. The server then sends additional malware components like RuntimeBroker and RemoteShellcode, which are designed to maintain persistence and elevate system privileges. The attackers exploit vulnerabilities in legitimate binaries such as fodhelper.exe and the CMSTPLUA COM interface to further increase their control over the infected system.

RuntimeBroker, a crucial element of ValleyRAT, acts as a secondary loader. Its main function is to fetch further malware from a remote C2 server, initiating a new infection cycle while incorporating techniques to detect and evade virtual environments. It also scans the Windows Registry for specific keys associated with popular Chinese applications like Tencent, WeChat, and Alibaba DingTalk, reinforcing the malware’s focus on Chinese systems.

RemoteShellcode, another component, serves as a downloader for the ValleyRAT backdoor. Upon execution, it establishes a network connection with the C2 server using UDP or TCP protocols. This connection enables the delivery of the ValleyRAT payload, granting attackers remote access to the compromised system. The malware’s capabilities include executing remote code, capturing screenshots, managing files, and loading additional plugins, making it a formidable threat.

The ANY.RUN sandbox provides valuable insights into ValleyRAT’s behavior, revealing that MSBuild.exe, a legitimate tool for building .NET projects, was used to execute a file in the Temp directory, suggesting an attempt to obfuscate malicious activity. Detection by Suricata IDS within the sandbox, showing attempts to communicate with a C2 server, indicates the possibility of malware infection using legitimate tools and covert communication methods.

More Articles & Posts