VMTech
Discuss a project

Silver Fox uses signed QN Wallpaper adware to deploy ValleyRAT

Silver Fox uses signed QN Wallpaper adware to deploy ValleyRAT

Signed adware used to conceal a backdoor

Kaspersky has identified a ValleyRAT distribution campaign attributed to the threat actor Silver Fox, in which attackers disguise the backdoor as a signed version of QN Wallpaper, a Chinese desktop-wallpaper application. The unmodified product is adware that bundles partner software and displays advertising, but the submitted installer contained a modified copy built to deliver malware.

ValleyRAT, also tracked as Winos 4.0, gives an operator extensive control over an infected Windows machine. Kaspersky said the campaign’s geography and payload indicate Silver Fox is the likely actor. Its analysis was based on a single installer submitted by a customer, and it did not assign a victim count to this particular delivery route.

DLL sideloading exploits trust in a signed process

The installer extracts the altered QN Wallpaper package and launches its signed executable, QnWallpaper.exe. That executable loads a malicious libcef.dll placed in the same directory, a technique known as DLL sideloading. The backdoor consequently executes inside a legitimately signed process, helping it avoid controls that rely on the executable’s signature.

Before the adware component begins, the installer disables Windows Defender through the DisableAntiSpyware registry key and adds itself to Windows autorun entries. If the current user does not have administrator privileges, it attempts to relaunch with runas. ValleyRAT can also designate its own process as critical, meaning an attempt to terminate it can trigger a blue screen of death.

Capabilities and indicators for defenders

Kaspersky described ValleyRAT as capable of collecting keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules. The adware features remain inactive while the infection chain executes. The abused download domain was qnwallpaper[.]keansoft[.]cn, while meeting[.]tencent[.]com was opened as a legitimate decoy page.

The reported host artifact is the installation path C:\Program Files\QNWallpaper\5.4.0.1662\, alongside the DisableAntiSpyware value. Kaspersky listed command-and-control infrastructure at 103.45.66.18 on ports 441, 442, and 443, and 192.253.225.173 on ports 6666 and 8888. The MD5 hashes include c24e99f9437feacaa63766a3cde3fe3d for the installer, 07ddbbe2c71c45577a7a4fbcdba0df91 for the malicious libcef.dll, and 8a626d844943da3456b044f38deae3a2.

Third-party software policy is an endpoint control

DLL sideloading through legitimate applications is already part of Silver Fox’s toolkit. Cato Networks documented the group’s use of legitimate applications for DLL sideloading in a campaign against a Japanese manufacturer roughly five weeks before Kaspersky’s report, and libcef.dll had appeared in a 2025 ValleyRAT loader. Kaspersky also tracked the group in a tax-themed campaign targeting organizations in India and Russia.

Across 2026, Kaspersky recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, primarily in China and India; that total covers the year’s overall ValleyRAT activity, not this campaign alone. For businesses, the immediate implication is to enforce clear rules for third-party software, block user-created security exclusions, and investigate signed applications that load unexpected DLLs.

#cybersecurity#malware#endpointsecurity#windowssecurity
Open analytics
On the site 0 views
min read 4 31.08.2026
Instagram

Silver Fox uses signed QN Wallpaper adware to deploy ValleyRAT

Open the post on Instagram ↗