Silver Fox is distributing ValleyRAT through a signed Chinese adware app, using DLL sideloading and trusted processes to evade security controls. Kaspersky linked the campaign to QN Wallpaper abuse, noted serious post-infection capabilities, and urged users and organizations to avoid questionable software and security exclusions. #SilverFox #ValleyRAT #QNWallpaper #Winos40 #Kaspersky
Keypoints
- Silver Fox is using ValleyRAT disguised as signed Chinese adware.
- The attackers abused QN Wallpaper to deliver the backdoor.
- DLL sideloading let the malware run inside a trusted process.
- ValleyRAT can steal data, take screenshots, and load extra modules.
- Kaspersky advised avoiding questionable software and exclusion lists.
Read More: https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html