ValleyRAT Backdoor Hides in Signed Adware Added to Antivirus Exclusions

Executive Summary

Silver Fox has been observed distributing the ValleyRAT backdoor by disguising it as the signed Chinese desktop‑wallpaper tool QN Wallpaper. The malware runs under the trusted adware process, allowing users who add the application to their antivirus exclusions to inadvertently install the backdoor.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-31T12:14:00+00:00 - Category: threat-intel

Original Description: The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool

"Do not turn back when you are just at the goal."

— Publilius Syrus
Source: The Hacker News