< Back to all clusters
[TECHNOLOGY] · China, India · 5 sources

started · updated

Silver Fox uses signed adware to distribute ValleyRAT backdoor

Cybersecurity researchers have identified a campaign where the threat actor Silver Fox uses signed adware to distribute the ValleyRAT backdoor. The attack primarily targets users in China and India.

The malware is disguised using a modified version of QN Wallpaper, a legitimate Chinese desktop wallpaper tool. The attackers utilize DLL sideloading, where a signed executable loads a malicious libcef.dll file from its own directory, allowing the backdoor to run under a trusted process. This technique helps the malware bypass security controls, especially if users have added the adware to their antivirus exclusions.

Once installed, ValleyRAT provides attackers with full control over the compromised machine. It is capable of capturing keystrokes, clipboard contents, and screenshots, as well as delivering additional malicious modules. The installer also attempts to disable Microsoft Defender via registry keys and can flag its own process as critical to prevent termination by triggering a blue screen of death. Researchers recorded over 100,000 detections of ValleyRAT and related malware during 2026.

Entities

Kaspersky · Microsoft Defender · QN Wallpaper · Securelist · Silver Fox