Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Adware Conceals ValleyRAT Backdoor in China and India

Adware Conceals ValleyRAT Backdoor in China and India

Posted on August 31, 2026 By CWS

Cybersecurity researchers have uncovered a malicious campaign that exploits adware to install the ValleyRAT backdoor on Windows systems. This attack, primarily targeting users in China and India, turns seemingly benign programs into vectors for unauthorized access and data theft.

Adware as a Trojan Horse

The attack initiates with an installer that, based on its filename, alters its apparent behavior. Different filenames result in the installation of a collaboration app, a browser, or the opening of a meeting-download page. While these actions distract the user, malicious components are secretly integrated into the system.

This activity was detected by Securelist researchers, who observed suspicious network traffic from what appeared to be a standard adware sample. Their investigation revealed that the adware’s advertised functionality was entirely absent. Instead, it executed a concealed sequence that deployed ValleyRAT through a modified wallpaper-management application.

Technical Exploitation Tactics

The attackers utilize a tampered version of QN Wallpaper, which employs DLL sideloading, a technique that exploits Windows’ behavior of loading supporting files from a program’s folder. This approach allows malicious code execution alongside legitimate applications, making it difficult to detect.

Additionally, the installer attempts to disable Microsoft Defender, using the DisableAntiSpyware registry key, thereby providing a shielded environment for the unauthorized activities. The backdoor’s persistence is maintained by creating file associations that ensure its activation upon reboot, and it can leverage administrator privileges to escalate its capabilities.

Surveillance and Defense Evasion

ValleyRAT is designed for both surveillance and remote control. It can record keystrokes, capture clipboard data, and gather system information, including operating system details and local network configurations. Attackers can also initiate screenshots and download additional tools, broadening their control over compromised systems.

Its defensive features pose challenges during incident response. Depending on its configuration, ValleyRAT can evade detection by security software and ensure its process is critical, risking system instability if terminated. This resilience complicates efforts to remove it from infected devices.

Preventive Measures and Recommendations

The discovery of this campaign underscores the importance of maintaining updated cybersecurity practices. Organizations should enforce strict policies regarding third-party software installations and educate employees about the risks of unvetted downloads. Individuals are advised to avoid dubious software and refrain from adding such programs to security exclusions.

Security teams should diligently monitor for unexpected installations of QN Wallpaper, suspicious DLL files, and unusual network connections. Prompt isolation of affected systems and comprehensive network scans are crucial to mitigating the impact of such infiltrations. This incident highlights the need for users to source software only from reputable publishers to prevent inadvertent exposure to hidden threats.

Cyber Security News Tags:Adware, Backdoor, China, cyber attack, Cybersecurity, data theft, DLL Sideloading, Hacking, India, Malware, Microsoft Defender, network security, Silver Fox, ValleyRAT, Windows backdoor

Post navigation

Previous Post: Kaspersky Product Zero-Day Exploit Unveiled by Nightmare Eclipse
Next Post: Enhancing Security with Anthropic’s New Compliance API

Related Posts

Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks Cyber Security News
Russian Hacker Exploits Google Gemini for Crypto Theft Russian Hacker Exploits Google Gemini for Crypto Theft Cyber Security News
Streamlined Patch Management for Endpoint Device Security Streamlined Patch Management for Endpoint Device Security Cyber Security News
TA446 Hackers Unleash DarkSword Kit on iOS Devices TA446 Hackers Unleash DarkSword Kit on iOS Devices Cyber Security News
A Scalable Solution for Global Privileged Access Management A Scalable Solution for Global Privileged Access Management Cyber Security News
MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SCALR AI: A Free AI Platform for Security Teams
  • ServiceNow Fixes Critical Code Injection Vulnerabilities
  • Enhancing Security with Anthropic’s New Compliance API
  • Adware Conceals ValleyRAT Backdoor in China and India
  • Kaspersky Product Zero-Day Exploit Unveiled by Nightmare Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SCALR AI: A Free AI Platform for Security Teams
  • ServiceNow Fixes Critical Code Injection Vulnerabilities
  • Enhancing Security with Anthropic’s New Compliance API
  • Adware Conceals ValleyRAT Backdoor in China and India
  • Kaspersky Product Zero-Day Exploit Unveiled by Nightmare Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark