PNGPlug Loader Delivers ValleyRAT Malware Through Fake Software Installers
Researchers studying cybersecurity are drawing attention to a number of cyberattacks that have used the well-known malware ValleyRAT to target Chinese-speaking areas such as Hong Kong, Taiwan, and Mainland China.
In a technical study released last week, Intezer stated that the attacks use a multi-stage loader called PNGPlug to deliver the ValleyRAT payload.
The first step in the infection chain is a phishing page, which is intended to trick victims into downloading a malicious Microsoft Installer (MSI) package that looks like genuine software.
When the installer is run, it secretly extracts an encrypted file that contains the malware payload while simultaneously launching a harmless application to allay suspicions read more about PNGPlug Loader Delivers ValleyRAT Malware Through ...

