importantSYS.SOURCE: The Hacker News• 2026-08-31T17:44:00+05:30
ValleyRAT Backdoor Exploits Signed Adware to Bypass Antivirus Exclusions
ValleyRAT, a sophisticated backdoor, is disguised as signed Chinese adware (QN Wallpaper) to bypass antivirus exclusions through DLL sideloading. The Silver Fox threat group uses this technique to gain full system control, with Kaspersky warning about risks from untrusted software and exclusion list vulnerabilities.
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
*** END OF TRANSMISSION ***