Observed Signal · Aug 18, 2026 · Market Signal · Source: Forcepoint · Impact: 3/5

Signed Overwolf Binary Sideloads ValleyRAT Malware in India Tax Scam

Executive Signal Summary

New X-Labs research by Raghu Ram (August 18, 2026) details a malware campaign using a signed Overwolf binary to sideload ValleyRAT in an India tax scam.

SIGNAL RADAR

Track Forcepoint Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: Forcepoint•Published: Aug 18, 2026

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

InfrastructureJul 6, 2026

AI-Agent 'Jadepuffer' Runs Adaptive Ransomware

Security researchers at Sysdig uncovered a novel ransomware attacker dubbed “Jadepuffer” that appears to be controlled by an AI agent. The agent used natural-language-driven code and rapid iterative problem-solving — in one case completing an adaptation in 31 seconds — to place ransomware. It exploited a vulnerability in the open-source Langflow framework to harvest unencrypted cloud credentials and API keys, which enabled lateral movement and persistent tasks. Jadepuffer targeted MySQL servers running the Alibaba Nacos configuration service, creating admin accounts and encrypting 1,342 configuration files before deleting originals. The attacker generated a ransom table with a Bitcoin wallet and Proton‑Mail contact; analysts report the wallet moved roughly 46 BTC across about 73 transactions. Researchers warn AI agents lower the skill barrier for automated, adaptive cyberattacks against unpatched systems.

Read assessment
Large Language Models (LLM) & AIMar 26, 2026

LiteLLM Malware Exposes Delve Compliance Claims

A severe supply‑chain malware infection was discovered in LiteLLM, a popular open‑source project that provides unified access to many AI models. Research scientist Callum McMahon of FutureSearch found the malware after his machine shut down following a LiteLLM download; the malicious code entered via a dependency, stole login credentials and propagated to other packages. Security firm Snyk reported LiteLLM downloads as high as 3.4 million per day and noted the project had ~40K GitHub stars. LiteLLM displayed SOC 2 and ISO 27001 certifications obtained through Delve, an AI‑powered compliance startup now accused elsewhere of misleading customers about conformity (Delve denies the allegations). LiteLLM says it is investigating with Mandiant and performing a forensic review; CEO Krrish Dholakia declined to comment on Delve’s role. The incident highlights risks in dependency management and limits of certification-based assurances.

Read assessment
Android mobile malware / security alertMay 8, 2026

New Android Trojans Target Over 800 Apps

Security researchers at Zimperium have identified four new Android trojans — RecruitRat, SaferRat, Astrinox and Massiv — that target banking and social-media applications. The trojans together aim at credentials and transaction theft across more than 800 apps. The malware can actively hide on infected devices (for example by replacing app icons with transparent images), remain dormant to evade initial scans, download additional payloads later, and hide malicious code inside ZIP structures. Researchers observed distribution vectors including fake job portals and illegal streaming sites; one trojan mimics the HR service Hirex. Users are advised to avoid sideloading apps from unknown websites and to use official app stores such as Google Play or trusted alternatives like F‑Droid.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.