ValleyRAT is spreading disguised as adware
released on 2026-08-31 @ 11:11:49 AM
Attackers are distributing the ValleyRAT backdoor disguised as legitimate Chinese adware called QN Wallpaper. The malicious installer deploys a modified version of the wallpaper management tool and uses DLL sideloading techniques to execute malicious code under a signed process. ValleyRAT is a sophisticated backdoor capable of keylogging, clipboard monitoring, screenshot capture, and delivering additional modules. The campaign has affected over 1,500 unique users, primarily in China and India, with more than 100,000 detections throughout 2026. Attribution points to the Silver Fox threat group, known for operating ValleyRAT. The attackers disabled Windows Defender, established persistence mechanisms, and implemented process protection techniques including marking processes as critical to trigger system crashes if terminated.