A campaign is using fake Microsoft Teams download sites to deliver the ValleyRAT malware, which is then installed via DLL sideloading to evade detection. The article does not provide a CVSS score, specific affected software versions, a fixed version, or a recommended workaround. Security teams should advise users to only download software from official vendor sources and monitor for suspicious DLL sideloading behavior.
2026-05-20 (Back to Inventory) Fake Microsoft Teams download sites are being used to deliver ValleyRAT via DLL sideloading Author(s): Srinivasan E Organization: K7 Security win.valley_rat Open article directly Open article on Archive.org Related Articles 2025-11-21 â‹… K7 Security â‹… Dhanush , Srinivasan E Brazilian Campaign: Spreading the Malware via WhatsApp 2025-09-30 â‹… K7 Security â‹… Uma Madasamy PatchWork APT 2025-08-22 â‹… K7 Security â‹… Harihara Sudhan Examining the tactics of BQTLOCK Ransomware & its variants BQTlock