ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Silver Fox is distributing ValleyRAT through a signed Chinese adware app, using DLL sideloading and trusted processes to evade security controls. Kaspersky linked the campaign to QN Wallpaper abuse, noted serious post-infection capabilities, and urged users and organizations to avoid questionable software and security exclusions. #SilverFox #ValleyRAT #QNWallpaper #Winos40 #Kaspersky

Keypoints

  • Silver Fox is using ValleyRAT disguised as signed Chinese adware.
  • The attackers abused QN Wallpaper to deliver the backdoor.
  • DLL sideloading let the malware run inside a trusted process.
  • ValleyRAT can steal data, take screenshots, and load extra modules.
  • Kaspersky advised avoiding questionable software and exclusion lists.

Read More: https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html