[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYjAS1alCMgpQeJb0ZV976wlgKWTpXAAyZ7naA8E3m7k":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"e4584378-a201-4eb1-a7e3-17709fd9b376","ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions","valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions-50276d","The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool","The Silver Fox threat actor is distributing the ValleyRAT backdoor by disguising it as a signed Chinese adware application called QN Wallpaper. This technique leverages DLL sideloading, where a malicious library is loaded by a legitimate, signed executable, allowing the malware to run under a trusted process and bypass security controls. The malware also disables Windows Defender and adds itself to autorun entries.","ValleyRAT backdoor disguised as signed adware uses DLL sideloading to evade detection.","ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions Swati KhandelwalAug 31, 2026Malware \u002F Endpoint Security The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack's geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. \"This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules,\" Kaspersky said in its analysis. The disguise relies on DLL sideloading. The installer unpacks a modified copy of QN Wallpaper and runs its signed executable, QnWallpaper.exe, which loads a malicious libcef.dll planted in the same directory. With the library executing inside a legitimately signed process, the backdoor runs without triggering controls that trust the signature. Before the adware component starts, the installer switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system's autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them. ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death. Kaspersky shared the following indicators of compromise (IoCs) - Hashes (MD5): c24e99f9437feacaa63766a3cde3fe3d (the submitted installer), 07ddbbe2c71c45577a7a4fbcdba0df91 (the malicious libcef.dll), and 8a626d844943da3456b044f38deae3a2 Command-and-control servers: 103.45.66.18 on ports 441, 442 and 443, and 192.253.225.173 on ports 6666 and 8888 Domains in the chain: qnwallpaper[.]keansoft[.]cn, the abused adware's download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy Host artifacts: the DisableAntiSpyware registry value and the install directory C:\\Program Files\\QNWallpaper\\5.4.0.1662\\ DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit. In a campaign against a Japanese manufacturer about five weeks earlier, Cato Networks documented what it called the group's \"newly observed abuse of legitimate applications for DLL sideloading,\" and the same libcef.dll filename had already featured in a 2025 ValleyRAT loader. Kaspersky itself tracked the group in an earlier tax-themed campaign against organizations in India and Russia. Kaspersky's account is based on a single installer submitted by a customer; its advertising features stay inert while the infection chain runs, and the report stops short of attaching a victim count to the adware route. Across 2026 the vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, a figure spanning all of the year's ValleyRAT activity rather than this campaign alone. Kaspersky also urged organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat. \"For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions' exclusion lists,\" the company said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, endpoint security, Malware, Windows Security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fvalleyrat-backdoor-hides-in-signed.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEj8OUY2TmBxA9RLM9yG0dnv8OShMmr_0KXcJUWtPvcTbFKQ-jmG4_6PyVNCNxQH9VacMVqmi3ZdmcHepDqoLT4XOl5AHZ6mnxmg_QrTUmK2D01fsjrBJKQ1KmlodLNjgbNp65TVoTslEHW5s1IqgFR8xYQWab9WQBvn30sYuM-xh7pSQfAKUOFi3v4q3Do\u002Fs1600\u002Fadblock.jpg","2026-08-31T12:14:00+00:00","2026-08-31T14:00:14.437166+00:00",8,[18,21,24,27],{"name":19,"type":20},"Silver Fox","threat_actor",{"name":22,"type":23},"QN Wallpaper","product",{"name":25,"type":26},"Kaspersky","vendor",{"name":28,"type":29},"DLL sideloading","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":30,"icon":32,"name":33,"slug":34},null,"Malware","malware",[36,41,43],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":42},{"id":30,"icon":32,"name":33,"slug":34},{"category":44},{"id":45,"icon":32,"name":46,"slug":47},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[49,53,56,59,63,66,70],{"type":50,"value":51,"context":52},"hash_md5","c24e99f9437feacaa63766a3cde3fe3d","Installer hash",{"type":50,"value":54,"context":55},"07ddbbe2c71c45577a7a4fbcdba0df91","Malicious libcef.dll hash",{"type":50,"value":57,"context":58},"8a626d844943da3456b044f38deae3a2","Unknown file hash",{"type":60,"value":61,"context":62},"ip","103.45.66.18","Command-and-control server IP on ports 441, 442, 443",{"type":60,"value":64,"context":65},"192.253.225.173","Command-and-control server IP on ports 6666, 8888",{"type":67,"value":68,"context":69},"domain","qnwallpaper[.]keansoft[.]cn","Abused adware download site",{"type":71,"value":72,"context":73},"mitre_attack","T1574.002","DLL Side-Loading"]