添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/04(火)
■件名
e-Tax 税務署 確定申告書
■添付ファイル
tax returns[.]zip -> tax returns.img -> tax returns.exe, taxreturns.dll, tax returns.exe.config
https://www.virustotal.com/gui/file/098944076200e38a2c97dd2cde6041e766fa8506d80a6c5ff9fbc90b2cdbf82b/detection
https://tria.ge/260804-xdx7vack4s/behavioral1
マルウェア #ValleyRAT
■通信先
hxxp://204.194.50[.]231/9856.png
■C2
204.194.50[.]231:449
引用元:
https://x.com/tdatwja/status/2084589989367889931
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/04(火)
■件名
【重要】契約書添付について
■リンク
hxxps[:]//hcnlskdfkxcvsdfjp.pages[.]dev
■ダウンロードファイル
202608045201545111[].zip -> Vat.N0.20260804083929.IMG -> Vat.N0.20260804083929.EXE, PdfcOrE8.dLL
https://www.virustotal.com/gui/file/eabb84ee06b664ae393b28e2847c1778fd875199c4b53d05f7c1cbf3443fb671
https://tria.ge/260804-wn5t1awgra/behavioral1
https://app.any.run/tasks/53367977-37b8-4336-bb38-c3aef082b691
https://urlscan.io/result/019fca6f-6369-76c2-b3c1-0707a9e58630/
マルウェア #ValleyRAT
■C2
haochisadnka[.]cc
(134.122.185[.]201:6698, 134.122.185[.]201:6685)
同一C2は7/27、8/3にも確認
https://infosec.exchange/@bomccss/116991299349148854
https://infosec.exchange/@bomccss/117031720574749123
引用元:
https://x.com/tdatwja/status/2084585961686749531
添付ファイルからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/04(火)
■件名
(楽楽明細)電子インボイス発行完了のお知らせ
■添付ファイル
RKM-20260709-1514[.]zip -> Tax_Notice_34015.img -> .exe, nvml.dll, NVML.DAT
https://www.virustotal.com/gui/file/93df03d7db7df23317ee87ebe3946ddff4364e45de5217b0c90c7925b22c8f04/details
https://tria.ge/260804-dslb2s1cqh/behavioral1
マルウェア #ValleyRAT
■C2
192.252.180[.]45:6666
同一件名の7/14までの攻撃と同一IPアドレス別ポート
https://infosec.exchange/@bomccss/116917898810735562
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/03(月)
■件名
[組織名] - 通知邮件
■リンク
hxxps[:]//dark-silence-5cba.erinbraumbachlianebl.workers[.]dev/
■ダウンロードファイル
JP-20260803123248.FDC1EEC62FDB[.]zip -> Vat.N0.20260803123012.IMG -> .EXE, PdfcOrE8.dLL
https://www.virustotal.com/gui/file/e0e1ae775ef8e530875235f035fb623b217d48fa810537144c872fcf41592648
https://tria.ge/260803-ppalxsyzgz/behavioral1
https://app.any.run/tasks/7e73f107-00f2-4808-80b5-1124234d3339
https://urlscan.io/result/019fc7b0-72b3-71ff-89ea-687cdfadeb7e/
マルウェア #ValleyRAT
■C2
ljdnxz[.]cc
(121.127.253[.]206:8856, 121.127.253[.]206:8868)
引用元:
https://x.com/tdatwja/status/2084216393948647508
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/03(月)
■件名
【ご請求書】7月分のご確認をお願いいたします
■リンク
hxxps[:]//kxjbvskdmxbdfgd.pages[.]dev/
■ダウンロードファイル
H-CZ_20260803001053[.]zip -> Vat.N0.20260803001049.IMG -> .EXE, PdfcOrE8.dLL
https://www.virustotal.com/gui/file/61a602b23169ad451a22661e2e356e16ef2bd3c7ef7a23d5892ac4f79baff0b5
https://tria.ge/260803-nr5z6swdpd/behavioral2
https://app.any.run/tasks/8f7eb9e0-41fb-4794-9bde-4922a9988868
マルウェア #ValleyRAT
■C2
haochisadnka[.]cc:6685,6698
(134.122.185[.]201:6698, 134.122.185[.]201:6685)
リンク先ドメインからのダウンロードは7/31から確認
https://urlscan.io/search/#kxjbvskdmxbdfgd.pages.dev
引用元:
https://x.com/tdatwja/status/2084212938697769447
ール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/08/03(月)
■件名
税務申告不適合及び罰則に関する通知 / 照会番号 NTA/COMP/PEN/2026-083
■リンク
hxxps[:]//kaiwyrey.eu[.]cc/d/fe93220bfecf/file?code=1082658a8855be82a6859324aef5153d
上記は既にアクセスできないが、同ドメインからのファイルダウンロードは引数を変え6日前から確認。
https://urlscan.io/search/#kaiwyrey.eu.cc
■ダウンロードファイル
20260731173614[.]zip -> VatN0.20260731173607.IMG -> .EXE, PdFcOrE8.DlL
https://www.virustotal.com/gui/file/12a22fece1fb6c9aa5620ae910b9b0a98b9013b0b8efb77369ec1bed40ddb18d
https://tria.ge/260803-pderhaxbqb/behavioral1
マルウェア #ValleyRAT
■C2
auk218[.]club
(118.107.0[.]196:7811, 118.107.0[.]196:7800)
引用元:
https://x.com/tdatwja/status/2084211029027016952
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Discover how the SilverFox ValleyRAT attack leverages fake invoices and DLL side-loading to bypass defenses and target Japanese industrial firms.
#SilverFox #ValleyRAT #Cybersecurity #PhishingAttack #MalwareAnalysis
https://meterpreter.org/silverfox-valleyrat-attack/?utm_source=mastodon&utm_medium=jetpack_social
securityaffairs
@securityaffairs@infosec.exchange
Pierluigi Paganini is a member of the ENISA (European Union Agency for Network and Information Security) Ad-Hoc Working Group on Cyber Threat Landscapes and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Pierluigi is a cyber security expert with over 25 years of experience in the field.
infosec.exchange
#SilverFox Targets Japanese Manufacturer With Advanced #ValleyRAT Campaign
https://securityaffairs.com/196347/apt/silverfox-targets-japanese-manufacturer-with-advanced-valleyrat-campaign.html
#securityaffairs #hacking #malware
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Cato CTRL details a new SilverFox ValleyRAT campaign in Japan using three BYOVD drivers and DLL sideloading to kill security tools.
#SilverFox #ValleyRAT #BYOVD #Winos40 #DLLSideloading #Malware #ThreatIntel #Cybersecurity
https://securityonline.info/silverfox-valleyrat-byovd-campaign/?utm_source=mastodon&utm_medium=jetpack_social
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/07/27(月)
■件名
只是一封通知邮件<組織名>的来信
※日本語訳:<組織名>からの通知メールです
■リンク
hxxps[:]//withered-lake-8596.krzakanna172.workers[.]dev/
(172.67.146[.]2)
■ダウンロード
J-A20260727022544[.]zip -> Vat[.]No.20260727022528.IMG ->
.EXE, PdFcOrE8.DlL
https://www.virustotal.com/gui/file/ee0ef34a4402dea54ec8b4e0557de9605a038a4f2b82380f2978296fd60f9791
https://tria.ge/260727-k1dqhack5x/behavioral1
https://app.any.run/tasks/a8a4d657-5a17-487d-b1e3-65d94c8e1d45
マルウェア #ValleyRAT
■C2
hxxp://haochisadnka[.]cc:6698/
(134.122.185[.]201:6698)
引用元:
https://x.com/tdatwja/status/2081650901660647436
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/07/21(火)
■件名
【重要】契約書添付について
■リンク
hxxps[:]//morning-cell-6811.nukisora1808.workers[.]dev/
■ダウンロード
20260721074431[.]zip -> No.20260721074047.IMG -> VAT_N0.20260721074047.EXE, pdfcOrE8.dlL
https://www.virustotal.com/gui/file/3e68ad68d4186a5a8cbb0471390879cfb05cfa2de35ae77b23cacfa3faed875b
https://tria.ge/260721-jezv6shy5p/behavioral2
https://app.any.run/tasks/aa3677a7-8261-413e-83f3-d03780e27567
マルウェア #ValleyRAT
■C2
134.122.185[.]201:6698
134.122.185[.]201:6685
引用元:
https://x.com/tdatwja/status/2079459160526352835
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/07/17(金)
■件名
税務コンプライアンス違反及び罰金に関する通知
■リンク
hxxps[:]//u110608428.ct.sendgrid[.]net/ls/click?upn=[略] -> hxxps[:]//isudcnzy.eu[.]cc/d/1b78c105d6b8
■ダウンロード
Tax-Number635863[.]zip -> Tax-Number635863.img -> .exe, jli.dll, 他正規DLL
https://www.virustotal.com/gui/file/77a03e8d48a0dca9c736d04dc6a6ab9aa74dc7445bea203937506da1edc03b44
https://tria.ge/260721-hy1q5sht9l/behavioral2
https://app.any.run/tasks/89ba9427-4678-48b3-8fe8-ab5c32bb22ec
マルウェア #ValleyRAT
■C2
103.59.103[.]30:8888
103.59.103[.]30:6666
yk.ggdy[.]com:8003
yk.ggdy[.]com:80
関連:
同一内容のメール、C2
https://infosec.exchange/@bomccss/116882991374358743
引用元:
https://x.com/tdatwja/status/2079455000229761469
メール本文中リンクからマルウェア感染を狙った日本語のメールが確認されています。
■日時
2026/07/07(火)
■件名
税務コンプライアンス違反及び罰金に関する通知
■リンク
hxxps[:]//isudcnzy[.]eu[.]cc/d/4a28a94fbf3d
■ダウンロード
Tax-Number725863[.]zip -> Tax-Number725863.img -> Tax-Number725863.exe, jli.dll 他正規dll4つ
※引用元とhashは異なる
https://www.virustotal.com/gui/file/37d6cf87e2a13631ec807a26e3debe1672542ca24b585ea8bbd088eaccdaa4a3
https://tria.ge/260708-gjckbsct8r
https://app.any.run/tasks/c14ed462-0cb3-4be4-8473-b5a7c5ea93e9
マルウェア #ValleyRAT
■C2
103.59.103[.]30
103.12.149[.]93
yk.ggdy[.]com
通信先の一部は以下と同一
https://infosec.exchange/@bomccss/116855336126896943
引用元:
https://x.com/tdatwja/status/2074728916196151641
You've seen all posts