iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A campaign reported on February 6, 2025 used counterfeit Google Chrome download sites to deliver ValleyRAT malware. According to The Hacker News’ account of Morphisec Threat Labs’ findings, victims downloaded a ZIP containing Setup.exe; a later stage used the legitimate Douyin executable to sideload a malicious DLL and launch ValleyRAT. The report does not establish whether the campaign remains active.
How ValleyRAT was installed
The reported infection chain separated the lure from the malware launch: the fake Chrome page supplied the initial file, but a Douyin executable—not Chrome—was used for DLL sideloading.
- Fake Chrome download site: Users searching for Chrome could reach a counterfeit download page offering a ZIP archive.
- Initial installer: The ZIP contained
Setup.exe. The report says it checked for administrator privileges and downloaded four additional payloads. - DLL sideloading: One payload was the legitimate
Douyin.exe. Attackers paired it with the roguetier0.dll; the executable loaded the malicious library, which launched ValleyRAT. - Process handling: The report says another DLL,
sscronet.dll, terminated processes appearing on an exclusion list.
This technique is also called DLL search-order hijacking: a legitimate signed program that can load a library is made to load a malicious one instead. In this incident, the reported vulnerable executable was associated with Douyin, not Google Chrome. The Hacker News’ February 6, 2025 report attributes these technical details to Morphisec Threat Labs.
Who the campaign targeted
The report characterizes the campaign as targeting Chinese-speaking users, citing Chinese-language web lures and applications. Morphisec CTO Michael Gorelik said: “This campaign specifically targeted Chinese-speaking users, as indicated by the use of Chinese-language web lures and applications aimed at data theft and evasion of defenses by the malware.” The Hacker News also reports Morphisec researcher Shmuel Uzan’s assessment that targeting increasingly included corporate roles in finance, accounting, and sales—positions that may have access to sensitive data and systems. Uzan said: “This actor has increasingly targeted key roles within organizations—particularly in finance, accounting, and sales department — highlighting a strategic focus on high-value positions with access to sensitive data and systems.”
#1 Best Overall
What ValleyRAT can do
The report describes ValleyRAT as C++ malware compiled in Chinese and lists capabilities including:
- Monitoring a victim’s screen and logging keystrokes.
- Establishing persistence and enumerating processes.
- Downloading and executing DLLs or other binaries.
These are reported capabilities, not evidence that every function was used in every infection. The Hacker News says ValleyRAT was first detected in 2023 and attributes this campaign to Silver Fox. It also mentions earlier activity affecting Chinese-speaking regions and prior delivery alongside Purple Fox and Gh0st RAT; those are historical associations reported by the article, not a measure of this campaign’s reach. The report does not provide a victim count or establish whether the sites or campaign are active now.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →

