ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

2026-09-01T02:51:37Z546ee538e5834d1250d4385d6d0db774bb74d395b0a8f31f9c70c938a286c1d0
China-linked espionageCisco routersClaudeDLL sideloadingFire AntGiveWPPaperCutRhysidaValleyRATWordPressactive exploitationcredential theftdata breachextortioninfostealerlog tamperingransomwareremote code executionrobotics securitysession hijacking

What happened

Security Affairs feed covering active exploitation of enterprise software flaws, malware delivery and infostealer activity, infrastructure compromise by a China-linked espionage group, ransomware and extortion claims, and vulnerabilities affecting WordPress, PaperCut, and Unitree G1 robots. The most urgent items are unauthenticated remote code execution in GiveWP and actively exploited PaperCut vulnerabilities, alongside campaigns involving ValleyRAT and Fire Ant.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
546ee538e5834d1250d4385d6d0db774bb74d395b0a8f31f9c70c938a286c1d0
Enrichment time
2026-09-01T02:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.