ValleyRAT Backdoor Disguised as Signed Adware

ValleyRAT Backdoor Disguised as Signed Adware

First seen 31 Aug 2026, 12:53 UTC Securelistencyclopedia.kaspersky.comThehackernews 71.8

Article Content

Browse articles
ThreatCluster

The Silver Fox threat actor has been distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, QN Wallpaper. This malware exploits DLL sideloading to operate under a trusted process, allowing it to evade detection by antivirus software. Once installed, ValleyRAT provides attackers with full control over the compromised machine, enabling them to collect sensitive data and execute additional malicious modules. The malware disables Windows Defender and adds itself to the system's autorun entries, ensuring persistence. Kaspersky has identified this campaign and provided indicators of compromise (IoCs) including specific MD5 hashes and command-and-control server IPs. Users are advised to avoid questionable software and not to add such applications to antivirus exclusions. The attack's geography and payload suggest a targeted approach by Silver Fox, which has a history of similar tactics. This incident highlights the dangers of adware and affiliate networks in cybersecurity.

Key Points: • ValleyRAT backdoor disguised as signed adware QN Wallpaper. • Malware uses DLL sideloading to evade antivirus detection. • Attackers can collect sensitive data and maintain control over compromised systems.

Timeline

2026-08-31
ValleyRAT backdoor identified
Kaspersky reported the ValleyRAT backdoor disguised as adware, highlighting its distribution method and capabilities.
The Hacker News
2026-08-31
Malware analysis published
Securelist published an analysis detailing the functionality and distribution of ValleyRAT masquerading as adware.
Securelist