ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
2026-09-01T08:51:35Z•0a5967a7d8ae7a4fccf54370dd1c94fefad59b343277f87629cba3e270745cca
API credential exposureChina-linked espionageCisco routersDLL sideloadingGiveWPPHP object injectionPaperCutRhysidaSilver FoxValleyRATWordPressactive exploitationcredential theftdata extortioninfostealerlog tamperingransomwareremote code executionrobotics securitysession hijacking
What happened
Security Affairs feed covering active exploitation, malware delivery and credential theft, cyber espionage, ransomware and extortion, and serious vulnerabilities in GiveWP, PaperCut, and Unitree G1 systems. Multiple reports describe high-impact risks including unauthenticated remote code execution, infrastructure compromise, session hijacking, and large-scale data theft.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 0a5967a7d8ae7a4fccf54370dd1c94fefad59b343277f87629cba3e270745cca
- Enrichment time
- 2026-09-01T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.