In a sophisticated new campaign, the notorious threat actor known as Silver Fox is deploying the potent ValleyRAT backdoor, cunningly disguised within legitimate-looking, signed Chinese adware. This insidious tactic exploits user trust and common security oversights, allowing the malware to operate under the radar, often within processes explicitly whitelisted by unsuspecting users.
The Deceptive Cloak: Adware as a Trojan Horse
Cybersecurity researchers at Kaspersky have uncovered the intricate details of this operation. Silver Fox has built its elaborate disguise around “QN Wallpaper,” a genuine Chinese desktop-wallpaper application. While QN Wallpaper itself is a form of adware—known for bundling partner applications and displaying ad banners—Silver Fox has weaponized a modified version of it. The brilliance of this strategy lies in its ability to leverage the perceived legitimacy of a signed application, even one with an already questionable reputation.
How ValleyRAT Infiltrates and Dominates
Once installed, ValleyRAT (also identified as Winos 4.0) grants the attacker complete, unfettered control over the compromised system. Kaspersky’s analysis strongly links the attack’s geographical focus and payload to the Silver Fox group, a collective with a history of similar sophisticated campaigns.
The core of the infiltration relies on a technique called DLL sideloading. The installer first unpacks a modified version of QN Wallpaper. It then executes the legitimate, signed QnWallpaper.exe. Crucially, a malicious libcef.dll is planted in the same directory. When QnWallpaper.exe runs, it inadvertently loads this malicious DLL, allowing ValleyRAT to execute its code within a trusted, signed process. This clever maneuver enables the backdoor to bypass security controls that typically rely on signature verification.
A Multi-Layered Attack Strategy
Before the adware component even fully initializes, the installer takes aggressive steps to solidify its presence and evade detection:
- It disables Windows Defender by manipulating the
DisableAntiSpywareregistry key. - It adds the malicious program to the system’s autorun entries, ensuring persistence across reboots.
- If the logged-in user lacks administrator rights, the malware relaunches itself using
runasto elevate its privileges.
ValleyRAT isn’t just about stealth; it’s also about resilience. It can flag its own process as “critical,” meaning any attempt to terminate it will trigger a devastating Blue Screen of Death (BSOD), effectively shutting down the system and preventing its removal.
ValleyRAT’s Potent Capabilities
This isn’t a mere nuisance; ValleyRAT is a highly sophisticated backdoor designed for extensive data exfiltration and control. Kaspersky highlights its alarming capabilities:
- Sensitive Data Collection: Capable of logging keystrokes and capturing clipboard contents.
- Surveillance: Can take screenshots of the compromised system.
- Modular Expansion: Designed to deliver and execute additional malicious modules, expanding its functionality as needed.
Indicators of Compromise (IoCs)
For cybersecurity professionals and vigilant users, Kaspersky has provided crucial Indicators of Compromise:
Hashes (MD5):
- Submitted installer:
c24e99f9437feacaa63766a3cde3fe3d - Malicious
libcef.dll:07ddbbe2c71c45577a7a4fbcdba0df91 - Additional hash:
8a626d844943da3456b044f38deae3a2
Command-and-Control (C2) Servers:
103.45.66.18on ports 441, 442, and 443192.253.225.173on ports 6666 and 8888
Domains in the Chain:
qnwallpaper[.]keansoft[.]cn(abused adware’s download site)meeting[.]tencent[.]com(legitimate page opened as a decoy)
Host Artifacts:
DisableAntiSpywareregistry value- Install directory:
C:Program FilesQNWallpaper5.4.0.1662
The Silver Fox Modus Operandi
DLL sideloading through signed, legitimate software is a hallmark of the Silver Fox group. This isn’t their first rodeo; Cato Networks previously documented the group’s “newly observed abuse of legitimate applications for DLL sideloading” in a campaign targeting a Japanese manufacturer, where the same libcef.dll filename was observed in a 2025 ValleyRAT loader. Kaspersky itself has tracked Silver Fox in earlier tax-themed campaigns against entities in India and Russia.
While this specific campaign’s victim count via the adware route remains unquantified by Kaspersky (based on a single customer submission where advertising features remained inert), the broader threat of ValleyRAT is significant. In 2026 alone, Kaspersky recorded over 100,000 detections of ValleyRAT and related malware, impacting more than 1,500 unique users, predominantly in China and India. This figure underscores the pervasive nature of this threat, extending beyond this particular adware-based distribution.
Protecting Your Digital Perimeter
The sophisticated nature of this attack highlights the critical need for robust cybersecurity practices. Kaspersky offers crucial advice for both individuals and organizations:
- Avoid Questionable Software:Exercise
extreme caution when installing software from unknown or untrusted sources. Even seemingly innocuous tools like wallpaper applications can harbor hidden dangers.
- Never Exclude Security Solutions: Perhaps most critically, never add software of questionable reputation to your security solutions’ exclusion lists. This creates a gaping hole in your defenses, precisely what Silver Fox exploits.
- Organizational Policies: For businesses, establishing clear, stringent policies regarding third-party software installation on work devices is paramount. Regular staff awareness training on emerging threats, especially those leveraging social engineering or deceptive tactics, is also vital.
The ValleyRAT backdoor serves as a stark reminder that even seemingly harmless adware can be a gateway to full system compromise. Vigilance, informed decision-making, and adherence to best security practices are your strongest defenses against such stealthy and dangerous threats.
For more details, visit our website.
Source: Link


Leave a comment