Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Man arrested after Swiss rave shooting that killed 22-year-old woman

    August 31, 2026

    Sir Mel Stride replaced as shadow chancellor amid Conservatives reshuffle

    August 31, 2026

    Leader of DOJ’s Civil Rights Unit Spars With Harvard, the Left and Her Colleagues

    August 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Man arrested after Swiss rave shooting that killed 22-year-old woman
    • Sir Mel Stride replaced as shadow chancellor amid Conservatives reshuffle
    • Leader of DOJ’s Civil Rights Unit Spars With Harvard, the Left and Her Colleagues
    • How Android 17 stops network snoops and SMS blasters now – with ECH and a 2G kill switch
    • ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
    • DeFi attacks expose $84 million price manipulation risk
    • Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case
    • More and more undergrads are living at home. That’s a crying shame – here’s why | Rohan Sathyamoorthy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 31
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 31, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 31, 2026Malware / Endpoint Security

    The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.

    Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners.

    Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack’s geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions.

    “This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules,” Kaspersky said in its analysis.

    Cybersecurity

    The disguise relies on DLL sideloading. The installer unpacks a modified copy of QN Wallpaper and runs its signed executable, QnWallpaper.exe, which loads a malicious libcef.dll planted in the same directory. With the library executing inside a legitimately signed process, the backdoor runs without triggering controls that trust the signature.

    Before the adware component starts, the installer switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system’s autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them.

    ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death.

    Kaspersky shared the following indicators of compromise (IoCs) –

    • Hashes (MD5): c24e99f9437feacaa63766a3cde3fe3d (the submitted installer), 07ddbbe2c71c45577a7a4fbcdba0df91 (the malicious libcef.dll), and 8a626d844943da3456b044f38deae3a2
    • Command-and-control servers: 103.45.66.18 on ports 441, 442 and 443, and 192.253.225.173 on ports 6666 and 8888
    • Domains in the chain: qnwallpaper[.]keansoft[.]cn, the abused adware’s download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy
    • Host artifacts: the DisableAntiSpyware registry value and the install directory C:Program FilesQNWallpaper5.4.0.1662

    DLL sideloading through signed, legitimate software is an established part of Silver Fox’s toolkit. In a campaign against a Japanese manufacturer about five weeks earlier, Cato Networks documented what it called the group’s “newly observed abuse of legitimate applications for DLL sideloading,” and the same libcef.dll filename had already featured in a 2025 ValleyRAT loader.

    Kaspersky itself tracked the group in an earlier tax-themed campaign against organizations in India and Russia.

    Cybersecurity

    Kaspersky’s account is based on a single installer submitted by a customer; its advertising features stay inert while the infection chain runs, and the report stops short of attaching a victim count to the adware route.

    Across 2026 the vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, a figure spanning all of the year’s ValleyRAT activity rather than this campaign alone.

    Kaspersky also urged organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat.

    “For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions’ exclusion lists,” the company said.

    Add Adware Antivirus Backdoor Exclusions hides signed users ValleyRAT
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft says Windows 11 KB5120998 update resets mouse settings

    Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

    China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

    Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

    Microsoft asks users to ignore ‘Antivirus is turned off’ errors

    More Details Emerge on Exploited PaperCut Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Man arrested after Swiss rave shooting that killed 22-year-old woman

    August 31, 2026

    Sir Mel Stride replaced as shadow chancellor amid Conservatives reshuffle

    August 31, 2026

    Leader of DOJ’s Civil Rights Unit Spars With Harvard, the Left and Her Colleagues

    August 31, 2026

    How Android 17 stops network snoops and SMS blasters now – with ECH and a 2G kill switch

    August 31, 2026
    Latest Posts

    The future of AI hinges on openness and cooperation. China and Britain can gain much by working together | Zheng Zeguang

    July 30, 2026

    Drought declared for whole of Wales amid sustained high temperatures

    July 30, 2026

    This 4,000-year-old city defied the rules of history

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Man arrested after Swiss rave shooting that killed 22-year-old woman

    August 31, 2026

    Sir Mel Stride replaced as shadow chancellor amid Conservatives reshuffle

    August 31, 2026

    Leader of DOJ’s Civil Rights Unit Spars With Harvard, the Left and Her Colleagues

    August 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.