<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Valleyrat on CuraSec</title><link>https://curasec.metacog.co.kr/tags/valleyrat/</link><description>Recent content in Valleyrat on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/valleyrat/index.xml" rel="self" type="application/rss+xml"/><item><title>ValleyRAT Backdoor Delivered via Signed Adware Abusing AV Exclusions</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-valleyrat-backdoor-hides-in-signed-adware-that-users-add-to/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-valleyrat-backdoor-hides-in-signed-adware-that-users-add-to/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Silver Fox&amp;rsquo;s technique of bundling a backdoor inside a legitimately-signed application and relying on user-added AV exclusions to stay resident is a design reminder to enforce allowlisting policies and audit AV exclusion lists across managed endpoints, but no direct cloud/app patch action follows from this report.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The evasion pattern — malware sheltered under a trusted signed process in a user-granted AV exclusion — is worth building a detection for: create or tune rules to alert on AV exclusion additions for unusual signed binaries and look for ValleyRAT IOCs once Kaspersky publishes them; no IOCs are available in this report to sweep against today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Silver Fox&amp;rsquo;s use of signed software to bypass endpoint controls illustrates how attacker-signed supply-chain lures undermine trust models; useful context for future board discussions on endpoint policy, but no same-week leadership action is warranted given no confirmed enterprise-sector targeting or widely-used vendor exposure.&lt;/li>
&lt;/ul></description></item></channel></rss>