Cyber News / Article / ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known asSilver Foxhas been observed distributing theValleyRATbackdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise aroundQN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners.
Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack's geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions.
"This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules," Kaspersky said inits analysis.
The disguise relies on DLL sideloading. The installer unpacks a modified copy of QN Wallpaper and runs its signed executable,QnWallpaper.exe, which loads a maliciouslibcef.dllplanted in the same directory. With the library executing inside a legitimately signed process, the backdoor runs without triggering controls that trust the signature.
Before the adware component starts, the installer switches off Windows Defender through theDisableAntiSpywareregistry key and adds the program to the system's autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself withrunasto acquire them.
ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death.
Kaspersky shared the following indicators of compromise (IoCs) -
DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit. In a campaign against a Japanese manufacturer about five weeks earlier,Cato Networks documentedwhat it called the group's "newly observed abuse of legitimate applications for DLL sideloading," and the samelibcef.dllfilename had already featured ina 2025 ValleyRAT loader.
Kaspersky itself tracked the group inan earlier tax-themed campaignagainst organizations in India and Russia.
Kaspersky's account is based on a single installer submitted by a customer; its advertising features stay inert while the infection chain runs, and the report stops short of attaching a victim count to the adware route.
Across 2026 the vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, a figure spanning all of the year's ValleyRAT activity rather than this campaign alone.
Kaspersky also urged organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat.
"For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions' exclusion lists," the company said.
Related articles
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
5 days ago
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
7 days ago
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
8 days ago
You might Also like

Malicious Chrome Extension Can Steal Login Sessions and Turn PCs Into Remote Backdoors

N-able Released Hotfix for RCE Vulnerability Affecting Platform

