Cyber Security News

ValleyRAT Mimic as LINE Installer Attacking Users to Steal Login Details

A sophisticated malware campaign has surfaced where threat actors are distributing the ValleyRAT backdoor disguised as a legitimate installer for the popular messaging application, LINE.

This targeted attack primarily focuses on Chinese-speaking users, leveraging a deceptive executable to infiltrate systems and compromise sensitive login credentials.

The malware employs a complex loading chain involving shellcode execution and legitimate system binaries to evade detection while establishing a firm foothold on the victim’s machine for long-term surveillance.

Upon execution, the fake installer triggers a multi-stage infection process designed to bypass endpoint security controls.

It immediately attempts to neutralize Windows Defender by using PowerShell commands to exclude entire system drives from antivirus scanning protocols.

Attack Flow (Source – Cybereason)

Simultaneously, it deploys a malicious library, identified as intel.dll, which performs rigorous environmental checks. These checks involve file locking and mutex creation to determine if the code is running within a sandbox.

If the environment is deemed safe, the malware unpacks its primary payload, effectively transforming the device into a fully compromised node.

Cybereason analysts identified this campaign and noted that the malware utilizes the advanced PoolParty Variant 7 injection technique.

This method allows the attackers to hide malicious activity within trusted system processes, significantly complicating detection.

By abusing Windows I/O completion ports, the malware injects code into legitimate processes, ensuring it can operate stealthily while harvesting user credentials and maintaining persistent communication with command-and-control servers.

Advanced Injection and Persistence Mechanisms

The technical complexity of this ValleyRAT variant is most evident in its evasion and persistence strategies.

The malware injects code into Explorer.exe and UserAccountBroker.exe, utilizing the latter process as a watchdog to ensure malicious components remain active.

Execution result of sysinternal tool sigcheck.exe (Source – Cybereason)

This injection relies on manipulating system handles via specific Windows APIs like ZwSetIoCompletion, allowing the threat actors to execute code within the memory space of trusted processes.

GUI of Fake Installer (Source – Cybereason)

Additionally, the malware actively scans for security products from vendors like Qihoo 360 and terminates their network connections to blind local defenses.

Execution result of certutil.exe (Source – Cybereason)

To maintain persistence, the malware registers scheduled tasks via Remote Procedure Call (RPC) protocols, ensuring automatic execution upon user login.

It also utilizes a digital certificate issued to “Chengdu MODIFENGNIAO Network Technology Co., Ltd” to appear legitimate, though the signature is cryptographically invalid.

To prevent infection, users must only download installers from official sources.

Security teams should configure detection rules to flag invalid certificates and monitor for suspicious child processes spawned by Explorer.exe, such as UserAccountBroker.exe, which indicates potential process hollowing activity.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

3 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

9 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

20 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago