Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers

The Hacker News by The Hacker News
January 21, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 21, 2025Ravie LakshmananCyber Attack / Windows Security

Cybersecurity researchers are calling attention to a series of cyber attacks that have targeted Chinese-speaking regions like Hong Kong, Taiwan, and Mainland China with a known malware called ValleyRAT.

The attacks leverage a multi-stage loader dubbed PNGPlug to deliver the ValleyRAT payload, Intezer said in a technical report published last week.

The infection chain commences with a phishing page that’s designed to encourage victims to download a malicious Microsoft Installer (MSI) package disguised as legitimate software.

Cybersecurity

Once executed, the installer deploys a benign application to avoid arousing suspicion, while also stealthily extracting an encrypted archive containing the malware payload.

“The MSI package uses the Windows Installer’s CustomAction feature, enabling it to execute malicious code, including running an embedded malicious DLL that decrypts the archive (all.zip) using a hardcoded password ‘hello202411’ to extract the core malware components,” security researcher Nicole Fishbein said.

These include a rogue DLL (“libcef.dll”), a legitimate application (“down.exe”) that’s used as a cover to conceal the malicious activities, and two payload files masquerading as PNG images (“aut.png” and “view.png”).

The main objective of the DLL loader, PNGPlug, is to prepare the environment for executing the main malware by injecting “aut.png” and “view.png” into memory in order to set up persistence by making Windows Registry changes and executing ValleyRAT, respectively.

ValleyRAT, detected in the wild since 2023, is a remote access trojan (RAT) that’s capable of providing attackers with unauthorized access and control over infected machines. Recent versions of the malware have incorporated features to capture screenshots and clear Windows event logs.

It’s assessed to be linked to a threat group called Silver Fox, which also shares tactical overlaps with another activity cluster named Void Arachne owing to the use of a command-and-control (C&C) framework called Winos 4.0.

Cybersecurity

The campaign is unique for its focus on the Chinese-speaking demographic and the use of software-related lures to activate the attack chain.

“Equally striking is the attackers’ sophisticated use of legitimate software as a delivery mechanism for malware, seamlessly blending malicious activities with seemingly benign applications,” Fishbein said.

“The adaptability of the PNGPlug loader further elevates the threat, as its modular design allows it to be tailored for multiple campaigns.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Power International Holding (PIH) schließt eine wegweisende Transaktion zur Finanzierung des Erwerbs von 100 % von Mobile Telecom – Service LLP (MTS) von Kazakhtelecom JSC ab

Power International Holding (PIH) schließt eine wegweisende Transaktion zur Finanzierung des Erwerbs von 100 % von Mobile Telecom - Service LLP (MTS) von Kazakhtelecom JSC ab

Recommended.

Le HUAWEI Mate XT | ULTIMATE DESIGN est lancé dans le monde entier et ouvre un nouveau chapitre dans la technologie pliable.

Le HUAWEI Mate XT | ULTIMATE DESIGN est lancé dans le monde entier et ouvre un nouveau chapitre dans la technologie pliable.

February 20, 2025
How AI Is Helping Kids Find the Right College

How AI Is Helping Kids Find the Right College

June 20, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio