Netskope Threat Labs

ValleyRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

ValleyRAT is a remote access trojan that provides backdoor access and data exfiltration capabilities, and researchers have tied its campaigns to Chinese speaking actors targeting gaming, cryptocurrency, and technology sectors. Its infections use driver based techniques to disable security tooling, and its operators push additional payloads onto compromised systems. The family's campaigns blend financial theft with surveillance, and its tooling continues to evolve.

First seen
April 2024
Last seen
October 2026
ValleyRatValleyrat
Alert Name
ByteCode-MSIL.Backdoor.ValleyRAT
ByteCode-MSIL.Trojan.ValleyRAT
Gen:Variant.ValleyRAT.34
Gen:Variant.ValleyRAT.5
Script-BAT.Trojan.ValleyRat
Script-BAT.Trojan.ValleyRAT
Trojan.ValleyRAT.1
Win32.Backdoor.Valleyrat
Win32.Backdoor.ValleyRAT
Win32.Dropper.ValleyRat