Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malware Evasion and Sophistication: The ValleyRAT Backdoor


Malware Evasion and Sophistication: The ValleyRAT Backdoor

  • ValleyRAT is a sophisticated backdoor malware detected in China and India, evading detection by using legitimate software as a cover.
  • The malware uses a modified version of QN Wallpaper to deliver malicious code via DLL sideloading.
  • ValleyRAT disables Windows Defender and creates persistence on the system using a registry key.
  • The malware collects sensitive data, takes screenshots, and delivers additional malicious modules.
  • The attackers linked to ValleyRAT are also associated with a campaign targeting a Japanese industrial manufacturer, adding to the malware's sophistication.



  • ValleyRAT is a sophisticated backdoor malware that has been detected in various systems, particularly in China and India. The malware is known to evade detection by using legitimate software as a cover, making it challenging for security experts to identify and remove.

    According to Kaspersky's latest analysis, ValleyRAT uses a modified version of QN Wallpaper, a legitimate Chinese desktop wallpaper application, to deliver the malware. The attackers modified the wallpaper application to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL. This technique allows the attackers to load their own code under the name of a legitimate application, making it difficult to detect.

    The malware also uses a registry key to disable Windows Defender and create persistence on the system. The installer also creates a separate process for the malicious library, libcef.dll, which is loaded by the wallpaper application. This allows the attackers to execute their own code under the name of a legitimate application, making it difficult to detect.

    ValleyRAT is capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules. The malware can also inject code into svchost.exe to restart the backdoor process if someone stops it. This makes it difficult to remove the malware, as it can continue to run even if the initial process is terminated.

    The attackers have also been linked to a campaign targeting a Japanese industrial manufacturer, which adds to the sophistication of the malware. The campaign includes two previously undocumented DLL-sideloading hosts, two kernel drivers not previously associated with the attackers, and a dual-layer recovery architecture that keeps ValleyRAT running even if defenders terminate individual components.

    In conclusion, ValleyRAT is a sophisticated backdoor malware that uses legitimate software as a cover to evade detection. The malware's use of DLL sideloading and registry keys makes it challenging to identify and remove. The attackers' use of a dual-layer recovery architecture and the linking to a campaign targeting a Japanese industrial manufacturer adds to the sophistication of the malware.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malware-Evasion-and-Sophistication-The-ValleyRAT-Backdoor-ehn.shtml

  • https://securityaffairs.com/198191/security/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool.html


  • Published: Mon Aug 31 16:39:39 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us