Ethical Hacking News
A sophisticated backdoor has been discovered hiding in signed adware, allowing threat actors to gain full control of compromised machines. ValleyRAT, a threat actor known as Silver Fox, disguises its malicious payload as a legitimate signed adware application, running the malware under a trusted process to evade detection. Kaspersky has shared indicators of compromise and urged users to be cautious of software with questionable reputation and to keep it away from security-tool exclusions.
ValleyRAT, a sophisticated backdoor, has been identified by Kaspersky as a malware threat disguised as a legitimate signed adware application. Silver Fox, a threat actor, uses DLL sideloading to distribute ValleyRAT, allowing the malware to run without detection. The malware hands the operator full control of the compromised machine and can evade security software by running under a trusted process. ValleyRAT switches off Windows Defender and adds itself to the system's autorun entries to persist. The malware can flag its own process as critical, triggering a blue screen of death if attempted to be terminated. Kaspersky has shared IoCs for ValleyRAT, including hashes, command-and-control servers, and domains. The threat actor, Silver Fox, has previously used DLL sideloading in other campaigns, highlighting the evolving tactics of the group.
The cybersecurity landscape has witnessed numerous high-profile attacks in recent years, each with its unique characteristics and methodologies. However, a latest threat actor has managed to evade detection through a rather ingenious means, disguising its malicious payload as a legitimate signed adware application. ValleyRAT, a sophisticated backdoor, has been identified by Russian cybersecurity vendor Kaspersky, which has been tracking the threat since its emergence in 2026.
According to Kaspersky, the threat actor known as Silver Fox has been observed distributing ValleyRAT disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. The malware, also tracked as Winos 4.0, hands the operator full control of the compromised machine.
The disguise relies on DLL sideloading, a technique where a malicious library is planted in a legitimate process, allowing the malware to run without triggering controls that trust the signature. In this case, the malicious library is libcef.dll, which is loaded into the same directory as the signed executable QnWallpaper.exe.
The installer of ValleyRAT unpacks a modified copy of QN Wallpaper, a genuine Chinese desktop-wallpaper tool, and runs its signed executable, QnWallpaper.exe, which loads the malicious libcef.dll into the same process. This allows the malware to run without being detected by security software.
Once installed, ValleyRAT switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system's autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them.
ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death, making it even more difficult for users to detect and remove the malware.
Kaspersky shared the following indicators of compromise (IoCs) for ValleyRAT, including hashes (MD5), command-and-control servers, domains in the chain, and host artifacts. The hashes are c24e99f9437feacaa63766a3cde3fe3d, 07ddbbe2c71c45577a7a4fbcdba0df91, and 8a626d844943da3456b044f38deae3a2.
The command-and-control servers are 103.45.66.18 on ports 441, 442, and 443, and 192.253.225.173 on ports 6666 and 8888. The domains in the chain are qnwallpaper[.]keansoft[.]cn, the abused adware's download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy.
Kaspersky also noted that this is not the first time Silver Fox has used DLL sideloading to distribute malware. In a campaign against a Japanese manufacturer about five weeks earlier, Cato Networks documented the group's "newly observed abuse of legitimate applications for DLL sideloading," and the same libcef.dll filename had already featured in a 2025 ValleyRAT loader.
Kaspersky itself tracked the group in an earlier tax-themed campaign against organizations in India and Russia. The vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, across 2026.
Kaspersky urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. The company also advised organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat.
"For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions' exclusion lists," Kaspersky said in its analysis.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Unseen-Threat-of-ValleyRAT-A-Sophisticated-Backdoor-Hides-in-Signed-Adware-ehn.shtml
https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
https://www.imtr.net/article/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions-13c2
Published: Mon Aug 31 08:25:35 2026 by llama3.2 3B Q4_K_M