Quick Takeaways
- Silver Fox leverages DLL sideloading of signed software, such as QN Wallpaper, to deploy ValleyRAT without detection, gaining full control of compromised systems.
- The malware can extract sensitive data, monitor keystrokes, capture screenshots, and load additional malicious modules, posing significant data theft risks.
- Attackers deactivate security defenses like Windows Defender and elevate privileges, making cleanup and detection challenging, especially on systems with weak security policies.
Threat Overview, Techniques, and Targets
Silver Fox, a threat actor, has been observed distributing a backdoor named ValleyRAT. They hide this malware inside a signed Chinese adware application. The adware is called QN Wallpaper, which is a real wallpaper tool that shows ads. The attackers disguise ValleyRAT by packaging it with this trusted application. They use a technique called DLL sideloading. This means the malware loads a malicious DLL file named libcef.dll, which runs inside a signed and legitimate process.
The attack starts when the installer runs and unpacks a modified version of QN Wallpaper. It then runs the signed QnWallpaper.exe while the malicious DLL loads in the background. To avoid detection, the installer turns off Windows Defender and adds the app to autorun so it starts with Windows. If the user does not have administrator rights, the malware self-relaunches with runas to gain necessary permissions. The malware can flag itself as critical, making it harder to shut down.
Victims of this attack include users who add questionable software to their antivirus exclusions. The targets are mainly organizations and users in China and India, but the malware has affected over 1,500 users across 2026. The attack relies on trusted signed processes to slip past security defenses.
Impact, Security Implications, and Remediation Guidance
ValleyRAT provides attackers full control over infected machines. It can collect keystrokes, clipboard data, take screenshots, and run additional malicious modules. Because ValleyRAT disables Windows Defender and adds itself to startup, it can remain hidden and persistent. The malware’s ability to flag its process as critical prevents easy termination. This increases the risk of long-term compromise.
The security implication is that signed adware can be used to hide malicious backdoors. Users and organizations need to be cautious about installing software from questionable sources. Additionally, adding such software to antivirus exclusion lists can allow malware to operate freely.
Remediation guidance should be obtained from the relevant vendor or security authority. Organizations should follow best practices, including reviewing software policies and monitoring for suspicious activity. Users are advised to avoid installing untrusted software and not to add questionable programs to security exceptions.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
