news.mlab.sh
Back to the feed
threat-intel

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

High
Summary

The threat actor Silver Fox is distributing the ValleyRAT backdoor disguised as a signed Chinese adware application (QN Wallpaper) to bypass antivirus protections. This sophisticated malware, tracked as Winos 4.0, allows remote control of compromised machines, collects sensitive data, and can even disable Windows Defender. Kaspersky detected over 100,000 ValleyRAT detections in 2026, primarily in China and India, highlighting the ongoing threat and urging users to avoid installing suspicious software and adding it to antivirus exclusions.

The threat actor Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese desktop-wallpaper tool, QN Wallpaper, to bypass antivirus protections. This malware, also known as Winos 4.0, provides the operator with full control over the compromised machine. Kaspersky’s analysis indicates that the attack’s geography and payload strongly point to Silver Fox as the likely group behind it.

ValleyRAT relies on DLL sideloading, where a modified copy of QN Wallpaper is unpacked and its signed executable, QnWallpaper.exe, loads a malicious libcef.dll planted in the same directory. This allows the backdoor to run without triggering controls that trust the signature of the legitimate software. Before the adware component starts, the installer switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system’s autorun entries.

If the logged-in user lacks administrator rights, ValleyRAT relaunches itself with runas to acquire them. ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death.

Kaspersky shared the following indicators of compromise (IoCs): - Hashes (MD5): c24e99f9437feacaa63766a3cde3fe3d (the submitted installer), 07ddbbe2c71c45577a7a4fbcdba0df91 (the maliciouslibcef.dll), and 8a626d844943da3456b044f38deae3a2 - Command-and-control servers: 103.45.66.18 on ports 441, 442 and 443, and 192.253.225.173 on ports 6666 and 8888 - Domains in the chain: qnwallpaper[.]keansoft[.]cn, the abused adware’s download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy.

Kaspersky tracked the group in an earlier tax-themed campaign against organizations in India and Russia. Across 2026, the vendor recorded more than 100,000 ValleyRAT detections affecting over 1,500 unique users, primarily in China and India. Kaspersky urges organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat, recommending users avoid installing software with a questionable reputation and, crucially, never adding such software to their security solutions’ exclusion lists.

Read the full article at The Hacker News