{"id":9812,"date":"2026-01-12T10:03:43","date_gmt":"2026-01-12T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/12\/valleyrat_s2-attacking-organizations-to-deploy-stealthy-malware-and-extract-financial-details\/"},"modified":"2026-01-12T10:03:43","modified_gmt":"2026-01-12T10:03:43","slug":"valleyrat_s2-attacking-organizations-to-deploy-stealthy-malware-and-extract-financial-details","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/12\/valleyrat_s2-attacking-organizations-to-deploy-stealthy-malware-and-extract-financial-details\/","title":{"rendered":"ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details"},"content":{"rendered":"<p>    ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new wave of attacks is using the ValleyRAT_S2 malware to quietly break into organizations, stay hidden for long periods, and steal sensitive financial information.<\/p>\n<p>ValleyRAT_S2 is the second-stage payload of the ValleyRAT family and is written in C++. Once inside a network, it behaves like a full remote access trojan, giving attackers strong control over infected systems and a reliable way to move data out.<\/p>\n<p>The current <a href=\"https:\/\/cybersecuritynews.com\/smartapesg-campaign-leverages-clickfix-technique\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> spreads mainly through fake Chinese-language productivity tools, cracked software, and trojanized installers that pose as AI-based spreadsheet generators.<\/p>\n<p>In many cases, the malware is delivered through <a href=\"https:\/\/cybersecuritynews.com\/hackers-employ-dll-side-loading\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL side\u2011loading<\/a>, where a legitimate signed application is tricked into loading a malicious DLL named like a normal library, such as steam_api64.dll.<\/p>\n<p>After tracking these operations, APOPHiS identified ValleyRAT_S2 as the core second-stage backdoor driving these intrusions.<\/p>\n<p>The malware also arrives through <a href=\"https:\/\/cybersecuritynews.com\/new-phising-attack-targeting-travellers\/\" target=\"_blank\" rel=\"noreferrer noopener\">spearphishing<\/a> attachments and abused software update channels.<\/p>\n<p>Malicious documents and archives drop payloads into locations like the Temp folder, for example:-<\/p>\n<p>C:UsersAdminAppDataLocalTempAI\u81ea\u52a8\u5316\u529e\u516c\u8868\u683c\u5236\u4f5c\u751f\u6210\u5de5\u5177\u5b89\u88c5\u5305steam_api64.dll.<\/p>\n<p>From there, Stage 1 focuses on evasion, while ValleyRAT_S2 takes over long-term control, system discovery, <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>, and financial data collection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiLtVr88hjvJJ_ysFiBZtx6nJdhH1hO-mVPWgZP2rMjeYiFZhSrTHmD38it0E4_04rGigQuO-xh8z85oN0qRIXkx4nZat_GjG1YTfT7YCeeUIKVTBnKUjH3PZax8MkA3IQ4z3yWIHnNTzZbJna1KM5L7gAS-dYShzUePcPdohMLeCOqLLxB-5H9GJ__2x8\/s16000\/File%2520info%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"File info (Source - Medium)\"><figcaption class=\"wp-element-caption\">File info (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>Once active, ValleyRAT_S2 scans processes, file systems, and registry keys, then reaches out to hardcoded command\u2011and\u2011control servers such as 27.124.3.175:14852 over a custom TCP protocol. It can upload and download files, run shell commands, inject payloads, and capture keystrokes.<\/p>\n<p>This makes it well-suited for harvesting online banking credentials, payment data, and internal financial documents.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-persistence-and-watchdog-behavior\"><strong>Persistence and watchdog behavior<\/strong><\/h2>\n<p>One of the most dangerous parts of ValleyRAT_S2 is its layered persistence and watchdog design, which helps it survive reboots and manual cleanup.<\/p>\n<p>The malware first stages files in the user\u2019s Temp and AppData paths, creating markers such as %TEMP%target.pid and configuration paths under %APPDATA%PromotionsTemp.aps.<\/p>\n<p>It also abuses Windows Task Scheduler through COM APIs to re\u2011run itself on startup, and may use registry run keys for backup startup paths.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEicK6WXIHSx05wA7dQJcyw1wPCECSo6DRTdJin7lyDxrR70-sMRv2CrZwGj1zVWmJXSPSVNlN3p9VmekzdK_sgyoDO0f0pmDBbG_A5wYe26LfT4rTntHU6iDpdO0LE1DPeSLhKfQJ68b2GmAbZ6hzwoG_wmqN-kHVb9sv-JTaJh9rC2QfYtmbjLnNIMr4c\/s16000\/Legitimate-looking%2520process%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"Legitimate-looking process (Source - Medium)\"><figcaption class=\"wp-element-caption\">Legitimate-looking process (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>A key feature is a generated batch script, monitor.bat, which acts as a watchdog loop.<\/p>\n<p>The script reads the stored process ID from target.pid, checks if the main malware process is still running, and silently restarts it if needed.<\/p>\n<p>A simplified version looks like this:-<\/p>\n<pre class=\"wp-block-code\"><code>@echo off\nset \"PIDFile=%TEMP%target.pid\"\nset \/p pid=&lt;\"%PIDFile%\"\ndel \"%PIDFile%\"\n:check\ntasklist \/fi \"PID eq %pid%\" | findstr &gt;nul\nif errorlevel 1 (\n  cscript \/\/nologo \"%TEMP%watch.vbs\"\n  exit\n)\ntimeout \/t 15 &gt;nul\ngoto check<\/code><\/pre>\n<p>This loop allows ValleyRAT_S2 to recover if security tools or admins kill the main process. Combined with structured exception handling, sandbox checks, and process injection into trusted names like Telegra.exe and WhatsApp.exe, the malware maintains a quiet but strong presence.<\/p>\n<p>For defenders, this means simple process killing is not enough; full removal must target the scheduled tasks, batch and <a href=\"https:\/\/cybersecuritynews.com\/vbscript-deprecation\/\" target=\"_blank\" rel=\"noreferrer noopener\">VBS<\/a> watchdog scripts, staged files, and the backdoor process all at once.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/valleyrat_s2-attacking-organizations\/\">ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/valleyrat_s2-attacking-organizations\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details A new wave of attacks is using the ValleyRAT_S2 malware to quietly break into organizations, stay hidden for long periods, and steal sensitive financial information. ValleyRAT_S2 is the second-stage payload of the ValleyRAT family and is written in C++. Once inside a network, it [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9812","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9812"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9812"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9812\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}