Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

UCL research discovers interesting properties of “space ice”

Five ways identity-based attacks are violating retail

Rondodox Botnet Exploits TBK DVR and 4 faithful router flaws launch Explaws DDOS attack

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fake Google Chrome Site Distributes ValleyRat Malware via Dll Hijack
Identity

Fake Google Chrome Site Distributes ValleyRat Malware via Dll Hijack

userBy userFebruary 6, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringFebruary 6, 2025LingeringRavy LakshmananCyber ​​Attacks/Malware

Fake Google Chrome Sites

The Bogus website advertises Google Chrome is used to distribute malicious installers for remote access trojans called Valleyrat.

The malware first detected in 2023 is attributed to threat actors tracked as Silver Fox and is primarily targeted at Chinese-speaking regions such as Hong Kong, Taiwan and mainland China.

“The actor is increasingly targeting key roles within the organization, particularly in the finance, accounting and sales sectors. He has a strategic focus on high value locations with access to sensitive data and systems. We are emphasizing that.” Week.

Cybersecurity

Early attack chains have been observed to provide valley rats along with other malware families such as purple foxes and GH0st rats, the latter being widely used in various Chinese hacking groups.

Like last month, the legitimate software counterfeit installer served as a distribution mechanism for Trojans using a DLL loader named PngPlug.

It is worth noting that a drive-by download scheme targeting Chinese-speaking Windows users was previously used to deploy GH0st rats using the malicious installer package of the Chrome web browser.

Fake Google Chrome Sites

In a similar way, the latest attack sequence related to ValleyRat involves using fake Google Chrome websites to trick the target into downloading a ZIP archive containing the executable file (“setup.exe”) ).

The binary checks if there is administrator privileges at runtime and downloads four additional payloads containing legal executables related to Douyin (“Douyin.exe”), the Chinese version of Tiktok. Masu. “tier0.dll”), launch ValleyRat malware.

It also retrieves another dll file (“sscronet.dll”). This is responsible for terminating any running processes that exist in the exclusion list.

Cybersecurity

Edited in Chinese and written in C++, Valleyrat is a Trojan horse designed to monitor screen content, log keystrokes and establish host persistence. You can also start communicating with a remote server, enumerating the processes and waiting for further instructions to allow you to download and run any DLLs, binaries, etc.

“Because of payload injection, the attacker abused a legitimately signed executable that was vulnerable to DLL search order hijacking,” Uzan said.

The development was due to the fact that Sophos avoided detection using Scalable Vector Graphics (SVG) attachments and shared details of a phishing attack that provides car-based keystroke loger malware such as Nymeria and Direct users to the qualification harvest page. is.

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article“Degrading”: Indian opposition MP protests US deportee return on the streets | Transition News
Next Article Openai co-founder John Schulman leaves humanity less than a year after joining an AI startup
user
  • Website

Related Posts

Five ways identity-based attacks are violating retail

July 8, 2025

Rondodox Botnet Exploits TBK DVR and 4 faithful router flaws launch Explaws DDOS attack

July 8, 2025

Over 17,000 fake news websites caught fuel supply investment scams worldwide

July 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

UCL research discovers interesting properties of “space ice”

Five ways identity-based attacks are violating retail

Rondodox Botnet Exploits TBK DVR and 4 faithful router flaws launch Explaws DDOS attack

Over 17,000 fake news websites caught fuel supply investment scams worldwide

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.