Cyber illustration of a hacker wolf and snarling rat holding a circuit board with the China flag, Telegram and Microsoft Teams icons, and glowing green code.

ValleyRat Remote Trojan Inside Popular App Installers

Category: Cybersecurity
Tags:

A new campaign is using fake installers for Telegram, WinSCP, Google Chrome, and Microsoft Teams to deploy the ValleyRat remote access trojan. Researchers at Nextron Systems report that the threat group Silver Fox is behind the operation. The attackers hide malicious components inside installers that look legitimate, so victims never suspect anything wrong. The campaign uses obfuscation, kernel-level drivers, and antivirus tampering to stay active on infected systems.

Relevant Source (Nextron Systems): Thor vs. Silver Fox – Uncovering and Defeating a Sophisticated ValleyRat Campaign
Nextron Systems documents the Silver Fox ValleyRat campaign that uses trojanized Telegram, Chrome, WinSCP, and Teams installers along with obfuscation, kernel drivers, and Defender tampering to maintain stealthy remote access.

Quick Facts

  • Attackers use trojanized installers for popular apps
  • Campaign attributed to the China-aligned Silver Fox group
  • Payload installs ValleyRat for long-term remote access
  • Installers show real interfaces while hidden malware executes
  • Malware disables Microsoft Defender using PowerShell exclusions
  • Persistence achieved through a scheduled task posing as a Windows component

How Fake App Installers Deliver Hidden Malware

Threat actors in this campaign deliver ValleyRat by wrapping malicious code inside modified installers for trusted applications. Victims often encounter these files through spear-phishing or ads that lead to counterfeit download pages. The installer interface looks normal but launches hidden processes that stage tools, extract encrypted archives, and run a driver-assisted payload chain.

  • Malicious components are stored in ProgramData to avoid attention
  • A renamed 7-Zip binary extracts encrypted archives
  • PowerShell commands disable antivirus controls

After the extraction, the main loader scans for security products and prepares the system for persistence. The entire process happens silently, leaving victims unaware until damage is done.

Relevant Source (Microsoft): Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware
Microsoft Threat Intelligence details how malvertising and fake software installers deliver malware, abuse trusted brands, and disable security tools, closely mirroring the techniques used in ValleyRat’s trojanized installer campaign.

ValleyRat Persistence With Scheduled Tasks

Attackers rely on ValleyRat because it provides stable remote access and supports covert communication with command-and-control servers. Nextron Systems found that the campaign uses multiple obfuscation layers and kernel-level techniques to avoid detection. The final stage installs a scheduled task disguised as a legitimate Windows item called WindowsPowerShell.WbemScripting.SWbemLocator.

  • Mimics genuine Windows naming to avoid suspicion
  • Runs encoded VBScript that launches the ValleyRat beacon
  • Ensures the trojan survives reboots and updates

This persistence method gives attackers a durable foothold, allowing them to revisit infected machines whenever needed.

Relevant Source (MITRE ATT&CK): Scheduled Task (T1053.005)
MITRE ATT&CK details how adversaries abuse Windows Task Scheduler to run malicious code for persistence, mirroring ValleyRat’s use of a disguised scheduled task to maintain long-term access.

Steps To Detect And Remove ValleyRat

Anyone who recently downloaded installers for Telegram, WinSCP, Chrome, or Teams from unofficial links should check their system. The campaign targets everyday users and small businesses that rely on common applications.

Steps to take now:

  1. Scan the system with a reputable offline antivirus tool
  2. Review scheduled tasks for suspicious or duplicate Windows items
  3. Check ProgramData for unknown directories such as WindowsData
  4. Reinstall affected applications from verified sources

A clean backup and system restore point can also help reverse the infection if performed early.

Relevant Source (CISA): Recovering From Viruses, Worms And Trojan Horses
This guidance from CISA outlines how to respond when malware infection is suspected, including running updated antivirus scans, manually reviewing suspicious tasks or files, and restoring from backups.

Why Trojanized Installers Keep Growing

Trusted applications give attackers a strong advantage because users rarely question installers from well-known brands. Silver Fox has refined this approach by combining familiar UIs with hidden malware stages that disable protections. The use of kernel-level drivers and Defender exclusions signals a shift toward deeper evasion and long-term control.

The broad use of spear-phishing and malicious ads increases exposure for home users and small businesses. Fake installers bypass traditional caution because the interface looks correct, and many victims do not verify file signatures or update history. These factors make trojanized installers a growing threat that requires stronger download hygiene and better endpoint monitoring.

Relevant Source (Trend Micro): Fake Installers Drop Malware and Open Doors for Opportunistic Attackers
Trend Micro analyzes how fake and trojanized software installers abuse trusted brands, malvertising, and user assumptions to deliver malware, matching the broader risks described in this section.

Practical Steps To Reduce Malware Risk

Users should rely only on official download portals and avoid third-party hosting sites. This campaign shows how attackers exploit brand trust to spread long-term remote access malware. A quick check of system tasks, ProgramData entries, and antivirus exclusions can help uncover infections early.

Relevant Source (CISA): Privacy and Mobile Device Apps
CISA outlines how to avoid malicious apps by limiting downloads to trusted, official sources and reviewing app behavior, which aligns directly with using official portals and basic checks to reduce infection risk.

Common Questions

How do I know if my installer was fake?
Fake installers often show correct interfaces but contain files with old timestamps or unusual hashes.

Does Microsoft Defender stop this threat?
Not in this campaign because the malware automatically adds a Defender exclusion for the entire drive.

Which apps are being impersonated?
Telegram, WinSCP, Google Chrome, and Microsoft Teams.

Is this related to normal software updates?
No. The malware uses counterfeit installers delivered through phishing or malicious ads.

Can ValleyRat steal data?
Yes. ValleyRat supports remote control, data theft, and long-term system access.

Remote Access Trojans (RATs): Risk, Impact, Protection

How JENI Strengthens System Security

JENI keeps Windows and macOS machines stable, clean, and less vulnerable to hidden malware components. A system free of junk files, broken dependencies, and outdated caches makes it harder for threats like ValleyRat to hide in obscure folders or blend into normal activity. JENI supports a healthier security posture by maintaining a clean environment where suspicious changes stand out.

What JENI Improves:

  • Deep cleanup that clears ProgramData clutter where many trojans try to hide
  • Repair routines that fix corrupted services attackers often target
  • Privacy-focused maintenance that removes leftover data from risky downloads

JENI fits naturally into a broader security strategy because stable systems are harder to compromise and easier to monitor. Removing unnecessary files limits the number of places malware can persist. Consistent repairs help keep core services working the way they should so attackers have fewer openings. Clean environments also make forensic checks simpler when users need to confirm whether an installer behaved as expected.

Published on December 3, 2025 at 10:09 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.