Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ValleyRAT Malware Concealed in Trusted Adware

ValleyRAT Malware Concealed in Trusted Adware

Posted on August 31, 2026 By CWS

A new threat has emerged from the cyber landscape as the threat actor known as Silver Fox has been distributing the ValleyRAT backdoor, cleverly disguised within a signed Chinese adware application. This strategy allows the malware to operate under trusted processes, bypassing user security by adding itself to antivirus exclusions.

The Mechanism Behind ValleyRAT

Security experts at Kaspersky have identified this malicious tactic, highlighting how ValleyRAT is concealed within QN Wallpaper, a legitimate Chinese desktop wallpaper tool. Typically, this application functions as adware, bundling partner software and displaying ads. However, when modified, it grants attackers full control over compromised systems, with the attack likely orchestrated by Silver Fox.

ValleyRAT, also known as Winos 4.0, is a sophisticated backdoor with capabilities to gather sensitive information such as keystrokes and clipboard contents, take screenshots, and deploy additional harmful modules. The use of DLL sideloading enables the execution of malicious code within a signed, trusted process, allowing it to evade detection.

Technical Details and Indicators of Compromise

The malware’s installer packs a modified version of QN Wallpaper, executing its signed file, QnWallpaper.exe, which in turn loads a malicious libcef.dll located in the same directory. This process circumvents security controls by running under a legitimate application signature.

Before the adware component begins its activities, the installer disables Windows Defender via the DisableAntiSpyware registry key and sets the program to run automatically. If the user lacks administrative privileges, the malware uses the runas command to escalate its permissions. Additionally, ValleyRAT can mark its process as critical, causing a system crash if termination is attempted.

Kaspersky provided several indicators of compromise, including specific hashes, command-and-control server IPs, and domains involved in the attack chain. These indicators offer a roadmap for identifying and mitigating the threat.

Impact and Mitigation Strategies

The use of signed, legitimate software for DLL sideloading is not new for Silver Fox. A previous campaign targeting a Japanese firm also employed similar tactics. Kaspersky’s findings are based on an analysis of a single installer submitted by a customer, indicating a broader, yet undetermined scope of attack.

Throughout 2026, more than 100,000 detections of ValleyRAT and related malware were recorded by Kaspersky, affecting over 1,500 users, predominantly in China and India. This data encompasses all ValleyRAT activities for the year, not just the current campaign.

Organizations are advised to establish stringent policies on the use of third-party software and to educate employees about potential risks. Kaspersky strongly recommends that individual users avoid installing software with dubious reputations and never include them in security tool exclusion lists.

The Hacker News Tags:Adware, antivirus exclusions, Backdoor, China, cyber attack, cyber threat, Cybersecurity, DLL Sideloading, endpoint security, India, Kaspersky, Malware, Silver Fox, Threat Actors, ValleyRAT

Post navigation

Previous Post: Ethereum Blockchain Exploited to Steal Card Data
Next Post: AI Security Threats Highlighted by Hugging Face Breach

Related Posts

A walkthrough of the Google Workspace Password Manager A walkthrough of the Google Workspace Password Manager The Hacker News
Rethinking Security for Scattered Spider Rethinking Security for Scattered Spider The Hacker News
Gainsight Expands Impacted Customer List Following Salesforce Security Alert Gainsight Expands Impacted Customer List Following Salesforce Security Alert The Hacker News
GhostJacking AI Attacks and New Cyber Threats Unveiled GhostJacking AI Attacks and New Cyber Threats Unveiled The Hacker News
Cloud Bucket Hijacking and Global Fraud: Key Cybersecurity Threats Cloud Bucket Hijacking and Global Fraud: Key Cybersecurity Threats The Hacker News
FortiClient EMS Flaw Exploited by Hackers for Data Theft FortiClient EMS Flaw Exploited by Hackers for Data Theft The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenClaw 2.0 Launches with Enhanced Security Features
  • AI Security Threats Highlighted by Hugging Face Breach
  • ValleyRAT Malware Concealed in Trusted Adware
  • Ethereum Blockchain Exploited to Steal Card Data
  • Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenClaw 2.0 Launches with Enhanced Security Features
  • AI Security Threats Highlighted by Hugging Face Breach
  • ValleyRAT Malware Concealed in Trusted Adware
  • Ethereum Blockchain Exploited to Steal Card Data
  • Hackers Target Critical Ruby on Rails Flaw for Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark