ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Silver Fox distributes ValleyRAT via signed QN Wallpaper adware, sideloading a malicious libcef.dll into a trusted process to evade defenses.
Kaspersky reports the Silver Fox threat actor disguising the ValleyRAT backdoor (Winos 4.0) inside a modified, signed copy of the QN Wallpaper adware tool, using DLL sideloading to run within a trusted process. The installer disables Windows Defender via the DisableAntiSpyware registry key, adds autorun entries, and elevates via runas when needed; ValleyRAT steals keystrokes, clipboard data, and screenshots and can mark its process critical to trigger BSOD if killed. Kaspersky recorded more than 100,000 ValleyRAT detections affecting over 1,500 unique users in 2026, mostly in China and India, with prior campaigns against Japan, India, and Russia.
- Malicious libcef.dll sideloaded by signed QnWallpaper.exe executes without tripping signature-based controls.
- ValleyRAT provides full machine control, capturing keystrokes, clipboard, and screenshots, and loading extra modules.
- Installer disables Windows Defender, sets autorun persistence, and relaunches with runas for admin rights.
- C2 servers 103.45.66.18 (ports 441-443) and 192.253.225.173 (ports 6666, 8888); decoy opens meeting.tencent[.]com.
- Kaspersky logged 100,000+ detections across 1,500+ users in 2026; technique also seen in Cato Networks' Japan case.
Full article589 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalAug 31, 2026Malware / Endpoint Security
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners.
Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack's geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions.
"This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules," Kaspersky said in its analysis.
The disguise relies on DLL sideloading. The installer unpacks a modified copy of QN Wallpaper and runs its signed executable, QnWallpaper.exe, which loads a malicious libcef.dll planted in the same directory. With the library executing inside a legitimately signed process, the backdoor runs without triggering controls that trust the signature.
Before the adware component starts, the installer switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system's autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them.
ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death.
Kaspersky shared the following indicators of compromise (IoCs) -
- Hashes (MD5):
c24e99f9437feacaa63766a3cde3fe3d(the submitted installer),07ddbbe2c71c45577a7a4fbcdba0df91(the maliciouslibcef.dll), and8a626d844943da3456b044f38deae3a2 - Command-and-control servers: 103.45.66.18 on ports 441, 442 and 443, and 192.253.225.173 on ports 6666 and 8888
- Domains in the chain: qnwallpaper[.]keansoft[.]cn, the abused adware's download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy
- Host artifacts: the
DisableAntiSpywareregistry value and the install directoryC:\Program Files\QNWallpaper\5.4.0.1662\
DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit. In a campaign against a Japanese manufacturer about five weeks earlier, Cato Networks documented what it called the group's "newly observed abuse of legitimate applications for DLL sideloading," and the same libcef.dll filename had already featured in a 2025 ValleyRAT loader.
Kaspersky itself tracked the group in an earlier tax-themed campaign against organizations in India and Russia.
Kaspersky's account is based on a single installer submitted by a customer; its advertising features stay inert while the infection chain runs, and the report stops short of attaching a victim count to the adware route.
Across 2026 the vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, a figure spanning all of the year's ValleyRAT activity rather than this campaign alone.
Kaspersky also urged organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat.
"For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions' exclusion lists," the company said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html