Is this a new ValleyRAT variant from SilverFox (ιΆη) or a completely new malware?
Custom protocol over TCP 443. C2 traffic starts with:
"BFuck" (42 46 75 63 6b 00 00 00)
IOCs:
πΎ 38.76.177.46:443
πΎ 43.99.101.175:443
https://t.co/tgPnjik7XG
The whole chain barely touches disk.
HTML β JScript β PowerShell β .NET loader β RAT, nearly all in memory.
Full writeup and IOCs from @RussianPanda9xx and Adam Mooney.
https://t.co/7OaPrMdDUR
@HuntressLabs@RussianPanda9xx You can get a verdict on the protocol from FlowCarp by submitting a PCAP like this:
curl --data-binary @βdesckvb-rat.βpcap https:β//demo.flowcarp.βcom
@HuntressLabs@RussianPanda9xx CapLoader and FlowCarp both identify the traffic to 48.202.58.22:7211 as "BlueLoader", which is a new RAT from PureCoder. The description of "DesckVB RAT" in your blog post also seem to match what we know about BlueLoader. Can you please verify if it is the same thing?
New release of CapLoader
π« JA3/JA4/SNI extraction from multi-segment TLS handshakes
π¨ Alerts on IOCs from @viql's RΓΆsti
π OSINT lookup on @jonasl's ScanMalware
π¦οΈExtracts packets from more encapsulation protocols
https://t.co/bbKCa8yutE
New tool released: #FlowCarp
ποΈIdentifies protocols without port numbers
π¨ Build protocol detection from example traffic
β‘οΈ Input: PCAP or PcapNG
β¬ οΈ Output: Flows and/or Alerts
https://t.co/3sqnfOpN4a
β¨ DFRWS EU 2026 Workshops
Led by Erik Hjelmvik (Netresec, Sweden), the session is designed for practitioners and researchers working with network and memory forensics in real-world investigations.
π Workshop Dates 23β24 March 2026
π§Ώ Details here: https://t.co/Aitqb7i2ua