Operation Silk Lure is the name given to an intrusion activity cluster associated with the weaponization of Windows scheduled tasks to facilitate DLL side-loading and deploy the ValleyRAT malware family. The operation is characterized by stealthy execution through legitimate task-scheduling mechanisms and abuse of DLL search-order behavior to load malicious code under the guise of trusted processes. This tradecraft indicates a focus on defense evasion, persistence, and post-compromise malware delivery. Publicly available information in this context does not establish a definitive sponsoring state, operator identity, victimology, or sector focus beyond the observed malware deployment chain. No corroborated aliases or subordinate groups are established beyond the operation name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.