Signal
Attackers abuse trusted software to deliver malware
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-08-31 09:46 UTCUpdated 2026-08-31 12:14 UTC
rss
malwaresupply_chainbrowser_extensionsbackdooradwarethreat_actor
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
Recent reporting highlights how attackers exploit trusted software channels. ValleyRAT was disguised as signed adware and delivered through an infection chain, while a separate campaign weaponized Chrome and Edge extensions through ownership changes and malicious updates. Together, the reports show how familiar software can become a delivery mechanism after installation or transfer of control.
Entities
KasperskySocketGoogleMicrosoftValleyRATQN WallpaperPavel Bukhtenko
Why now
- Fresh reporting documents both a ValleyRAT delivery chain and a separate browser-extension campaign.
- The cases involve software users may already trust, install deliberately, or update automatically.
- The reports broaden the warning from malicious downloads to post-install and post-acquisition abuse.
Why it matters
- Signed or previously trusted software can make malicious delivery harder for users and security controls to recognize.
- Automatic extension updates can expose existing users to later-added malicious code.
- Ownership changes create a software supply-chain risk beyond the initial installation decision.
Evidence assessment
Recurring claims
- ValleyRAT was distributed through software presented as adware, with the sample triggering an infection chain rather than providing functioning advertising features.
- The ValleyRAT campaign used signed software and relied on users adding the application to antivirus exclusions.
- A separate campaign turned legitimate or initially clean Chrome and Edge extensions into malware through acquisition and later updates.
How sources frame it
- Kaspersky: neutral
- The Hacker News: neutral
- Socket: neutral
The cluster links two distinct reports through a common theme: attackers abusing trusted software and user trust to deliver malware.
All evidence
All evidence
Kaspersky analysis of ValleyRAT disguised as adware
securelist.com · securelist.com · 2026-08-31 10:00 UTC
The Hacker News report on ValleyRAT in signed adware
thehackernews.com · thehackernews.com · 2026-08-31 12:14 UTC
CSO Online report on weaponized Chrome and Edge extensions
csoonline.com · csoonline.com · 2026-08-31 09:46 UTC
Show filters & breakdown
Evidence items loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3