Thehackernews
ValleyRAT Backdoor Disguised as Signed Adware
Article Content
The ValleyRAT backdoor has been discovered masquerading as a legitimate adware application, specifically a modified version of QN Wallpaper. This malware, attributed to the threat actor Silver Fox, utilizes DLL sideloading to evade detection and gain control over infected systems. The attackers disable Windows Defender and create persistence through registry modifications. The backdoor can collect sensitive data, including keystrokes and screenshots, while appearing as a harmless installation. Kaspersky's analysis revealed that the adware's advertising functionality is non-operational, serving only as a cover for the malicious payload. Users are advised to avoid adding such software to antivirus exclusions and to be cautious of applications with dubious reputations. The attack highlights the risks associated with seemingly benign software that can be exploited for malicious purposes.
Key Points: • ValleyRAT is disguised as a legitimate adware application, QN Wallpaper. • The malware uses DLL sideloading to evade detection and gain control of systems. • Users should avoid adding suspicious software to antivirus exclusions.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.