Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

GST-themed ValleyRAT campaign targeting Indian users

0
Medium
Published: 08/19/2026 (08/19/2026, 13:22:14 UTC)
Source: Reddit Cybersecurity

Description

A malware campaign targeting Indian users leverages a GST-themed lure to distribute ValleyRAT, a remote access trojan. The campaign uses a Microsoft-signed executable for DLL sideloading, employs process injection, UAC bypass, and security product tampering to evade detection. It features keylogging, screenshot capture, clipboard theft, and multiple command-and-control endpoints with a complex delivery infrastructure. The campaign is actively analyzed with indicators of compromise and infrastructure details published.

Reddit Discussion

r/cybersecurity·posted by u/unknownhad
00

I found a malware sample masquerading as an overdue Indian GSTR-3B filing notice. The lure references the 20 August filing deadline, reversing it led to a larger ValleyRAT / Silver Fox chain.

TL;DR of post:
• Microsoft-signed executable abused for DLL sideloading
• modified Microsoft DLL
• RuntimeBroker process injection
• UAC bypass mechanisms
• security-product/Defender tampering
• keylogging + screenshot + clipboard capabilities
• multiple C2 endpoints
• backup infrastructure
• 15-subdomain delivery infrastructure with victim-specific links

Full reversing/infrastructure analysis and IOCs:

https://blog.himanshuanand.com/2026/08/someone-is-filing-your-gst-return-and-it-is-not-your-ca/
Anyone here has observed the same infrastructure or related ValleyRAT samples recently?

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:22:14 UTC

Technical Analysis

This campaign uses a malicious Microsoft-signed executable abused for DLL sideloading combined with a modified Microsoft DLL to execute ValleyRAT malware. It injects into the RuntimeBroker process and bypasses User Account Control (UAC) to maintain persistence and evade user prompts. The malware tampers with security products including Windows Defender, enabling keylogging, screenshot capture, and clipboard data theft. The infrastructure includes multiple command-and-control endpoints and a 15-subdomain delivery system with victim-specific links. The campaign targets Indian users with a GST filing-themed social engineering lure referencing the GSTR-3B filing deadline. Detailed reversing and infrastructure analysis with IOCs are publicly available.

Potential Impact

The campaign compromises victim systems by installing ValleyRAT, enabling attackers to capture sensitive information such as keystrokes, screenshots, and clipboard contents. It also disables or interferes with security products, increasing the risk of prolonged undetected access. The use of multiple C2 endpoints and backup infrastructure suggests resilience and potential for widespread impact on targeted users.

Defensive Guidance

No official patch or fix is applicable as this is a malware campaign rather than a software vulnerability. Defenders should apply recommended detection and response measures based on the published IOCs and infrastructure analysis. Users should be cautious of GST-themed phishing lures and avoid executing unexpected attachments or links. Security products should be kept updated, and behavioral detection tuned to identify DLL sideloading and process injection techniques described in the analysis.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:campaign","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["campaign"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a85bc0aacd9273b492f27a6

Added to database: 08/19/2026, 14:22:02 UTC

Last enriched: 08/19/2026, 14:22:14 UTC

Last updated: 08/19/2026, 20:22:04 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses