← Back to feed
Threat Actors & CampaignsEmerging1 sourceJun 25, 2026 · 09:27via Netresec

Ping32 RMM and ValleyRAT

Brief

Fareed Radzi recently blogged about a malware campaign observed earlier in June by Kaspersky’s GReAT team. The malware campaign embedded malicious code in VBScripts, which were distributed through WhatsApp DMs. The VBScript then dropped the legitimate Remote Monitoring and Management (RMM) tool ManageEngine Endpoint Central.

Fareed included the IOCs for the following Endpoint Central server IP addresses:

  • 202.61.160.208
  • 202.61.160.202
  • 202.61.160.201
  • 202.61.160.160
  • 202.61.160.137
  • 38.55.151.63

He also noted a link to ValleyRAT :

Notably, 202.

  • 160[. ]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity.
Read more on Netresec