← Back to Feed

Fake Installer: Ultimately, ValleyRAT infection

February 3, 2026 · Cybereason · Severity: HIGH

Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them. In this Threat Analysis report, Cybereason Security Services investigates a fake installer attack we recently observed multiple times. We identified some findings that have not been documented in previous reports and obtained new threat intelligence insights from the malwares.

Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them.

In this Threat Analysis report, Cybereason Security Services investigates a fake installer attack we recently observed multiple times. We identified some findings that have not been documented in previous reports and obtained new threat intelligence insights from the malwares.

Key Takeaways

  • Cybereason Security Services investigated a fake installer campaign leading to ValleyRAT infection.
  • The Threat Analysis report provides practical recommendations for protecting against the threat.
  • Fake installers are used as a delivery mechanism for ValleyRAT malware.
☕ Buy a Coffee