ValleyRAT Backdoor Disguised as Signed Adware

ValleyRAT Backdoor Disguised as Signed Adware

First seen 31 Aug 2026, 12:53 UTC Securelistencyclopedia.kaspersky.comThehackernewsCybersecuritynewsSecurityaffairs.Co+11 64.5

Article Content

Browse articles
ThreatCluster

The ValleyRAT backdoor has been discovered masquerading as a legitimate adware application, specifically a modified version of QN Wallpaper. This malware, attributed to the threat actor Silver Fox, utilizes DLL sideloading to evade detection and gain control over infected systems. The attackers disable Windows Defender and create persistence through registry modifications. The backdoor can collect sensitive data, including keystrokes and screenshots, while appearing as a harmless installation. Kaspersky's analysis revealed that the adware's advertising functionality is non-operational, serving only as a cover for the malicious payload. Users are advised to avoid adding such software to antivirus exclusions and to be cautious of applications with dubious reputations. The attack highlights the risks associated with seemingly benign software that can be exploited for malicious purposes.

Key Points: • ValleyRAT is disguised as a legitimate adware application, QN Wallpaper. • The malware uses DLL sideloading to evade detection and gain control of systems. • Users should avoid adding suspicious software to antivirus exclusions.

Ask AI about this cluster

Timeline

2026-08-31
ValleyRAT backdoor identified
Kaspersky reported the discovery of ValleyRAT disguised as QN Wallpaper, highlighting its use of DLL sideloading.
Securelist
2026-08-31
Attack attributed to Silver Fox
The threat actor Silver Fox is linked to the distribution of ValleyRAT, utilizing modified adware for malware delivery.
Thehackernews
2026-08-31
Kaspersky analysis released
Kaspersky's analysis detailed the infection method and functionality of ValleyRAT, emphasizing its stealthy operation.
Securityaffairs.Co