GST-themed ValleyRAT campaign targeting Indian users
A malware campaign targeting Indian users leverages a GST-themed lure to distribute ValleyRAT, a remote access trojan. The campaign uses a Microsoft-signed executable for DLL sideloading, employs process injection, UAC bypass, and security product tampering to evade detection. It features keylogging, screenshot capture, clipboard theft, and multiple command-and-control endpoints with a complex delivery infrastructure. The campaign is actively analyzed with indicators of compromise and infrastructure details published.
AI Analysis
Technical Summary
This campaign uses a malicious Microsoft-signed executable abused for DLL sideloading combined with a modified Microsoft DLL to execute ValleyRAT malware. It injects into the RuntimeBroker process and bypasses User Account Control (UAC) to maintain persistence and evade user prompts. The malware tampers with security products including Windows Defender, enabling keylogging, screenshot capture, and clipboard data theft. The infrastructure includes multiple command-and-control endpoints and a 15-subdomain delivery system with victim-specific links. The campaign targets Indian users with a GST filing-themed social engineering lure referencing the GSTR-3B filing deadline. Detailed reversing and infrastructure analysis with IOCs are publicly available.
Potential Impact
The campaign compromises victim systems by installing ValleyRAT, enabling attackers to capture sensitive information such as keystrokes, screenshots, and clipboard contents. It also disables or interferes with security products, increasing the risk of prolonged undetected access. The use of multiple C2 endpoints and backup infrastructure suggests resilience and potential for widespread impact on targeted users.
Mitigation Recommendations
No official patch or fix is applicable as this is a malware campaign rather than a software vulnerability. Defenders should apply recommended detection and response measures based on the published IOCs and infrastructure analysis. Users should be cautious of GST-themed phishing lures and avoid executing unexpected attachments or links. Security products should be kept updated, and behavioral detection tuned to identify DLL sideloading and process injection techniques described in the analysis.
Affected Countries
India
GST-themed ValleyRAT campaign targeting Indian users
Description
A malware campaign targeting Indian users leverages a GST-themed lure to distribute ValleyRAT, a remote access trojan. The campaign uses a Microsoft-signed executable for DLL sideloading, employs process injection, UAC bypass, and security product tampering to evade detection. It features keylogging, screenshot capture, clipboard theft, and multiple command-and-control endpoints with a complex delivery infrastructure. The campaign is actively analyzed with indicators of compromise and infrastructure details published.
Reddit Discussion
I found a malware sample masquerading as an overdue Indian GSTR-3B filing notice. The lure references the 20 August filing deadline, reversing it led to a larger ValleyRAT / Silver Fox chain.
TL;DR of post:
• Microsoft-signed executable abused for DLL sideloading
• modified Microsoft DLL
• RuntimeBroker process injection
• UAC bypass mechanisms
• security-product/Defender tampering
• keylogging + screenshot + clipboard capabilities
• multiple C2 endpoints
• backup infrastructure
• 15-subdomain delivery infrastructure with victim-specific links
Full reversing/infrastructure analysis and IOCs:
https://blog.himanshuanand.com/2026/08/someone-is-filing-your-gst-return-and-it-is-not-your-ca/
Anyone here has observed the same infrastructure or related ValleyRAT samples recently?
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign uses a malicious Microsoft-signed executable abused for DLL sideloading combined with a modified Microsoft DLL to execute ValleyRAT malware. It injects into the RuntimeBroker process and bypasses User Account Control (UAC) to maintain persistence and evade user prompts. The malware tampers with security products including Windows Defender, enabling keylogging, screenshot capture, and clipboard data theft. The infrastructure includes multiple command-and-control endpoints and a 15-subdomain delivery system with victim-specific links. The campaign targets Indian users with a GST filing-themed social engineering lure referencing the GSTR-3B filing deadline. Detailed reversing and infrastructure analysis with IOCs are publicly available.
Potential Impact
The campaign compromises victim systems by installing ValleyRAT, enabling attackers to capture sensitive information such as keystrokes, screenshots, and clipboard contents. It also disables or interferes with security products, increasing the risk of prolonged undetected access. The use of multiple C2 endpoints and backup infrastructure suggests resilience and potential for widespread impact on targeted users.
Defensive Guidance
No official patch or fix is applicable as this is a malware campaign rather than a software vulnerability. Defenders should apply recommended detection and response measures based on the published IOCs and infrastructure analysis. Users should be cautious of GST-themed phishing lures and avoid executing unexpected attachments or links. Security products should be kept updated, and behavioral detection tuned to identify DLL sideloading and process injection techniques described in the analysis.
Affected Countries
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:campaign","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["campaign"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a85bc0aacd9273b492f27a6
Added to database: 08/19/2026, 14:22:02 UTC
Last enriched: 08/19/2026, 14:22:14 UTC
Last updated: 08/19/2026, 20:22:04 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.