research poc
ValleyRAT Campaign Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection to Evade DetectionValleyRAT
A recent ValleyRAT campaign employs RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade endpoint security detection. The malware achieves stealth by decrypting and injecting shellcode into a legitimate Windows process, bypassing traditional signature-based and behavioral defenses.