ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

2026-09-01T08:51:35Z0a5967a7d8ae7a4fccf54370dd1c94fefad59b343277f87629cba3e270745cca
API credential exposureChina-linked espionageCisco routersDLL sideloadingGiveWPPHP object injectionPaperCutRhysidaSilver FoxValleyRATWordPressactive exploitationcredential theftdata extortioninfostealerlog tamperingransomwareremote code executionrobotics securitysession hijacking

What happened

Security Affairs feed covering active exploitation, malware delivery and credential theft, cyber espionage, ransomware and extortion, and serious vulnerabilities in GiveWP, PaperCut, and Unitree G1 systems. Multiple reports describe high-impact risks including unauthenticated remote code execution, infrastructure compromise, session hijacking, and large-scale data theft.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0a5967a7d8ae7a4fccf54370dd1c94fefad59b343277f87629cba3e270745cca
Enrichment time
2026-09-01T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.