Kaspersky Details Silver Fox ValleyRAT Campaign Using Signed Chinese Adware

Published:

Kaspersky has disclosed details of a new cyber campaign in which the threat actor known as Silver Fox is distributing the ValleyRAT backdoor by disguising it as a signed Chinese adware application. According to the security company, the attackers built the campaign around QN Wallpaper, a legitimate Chinese desktop wallpaper application that normally functions as adware by displaying advertisements and bundling partner software. By modifying the application while retaining its trusted appearance, the attackers were able to execute ValleyRAT, also known as Winos 4.0, inside a signed process, increasing the likelihood that users who exclude such software from antivirus scanning would unknowingly allow the malware to operate. Kaspersky attributed the campaign to Silver Fox based on the attack’s characteristics, geographic focus, and malware payload, while advising users to avoid installing software with questionable reputations and to never place such applications on antivirus exclusion lists.

According to Kaspersky, the infection chain relies on DLL sideloading to execute the malicious payload. The installer extracts a modified version of QN Wallpaper and launches its signed executable, QnWallpaper.exe, which automatically loads a malicious libcef.dll file placed within the same directory. Since the malicious library is executed through a legitimately signed application, the malware is able to bypass certain security mechanisms that trust the application’s digital signature. Before launching the adware component, the installer disables Windows Defender by modifying the DisableAntiSpyware registry key and creates autorun entries to maintain persistence after system reboots. If the current user does not have administrator privileges, the malware relaunches itself using the Windows runas function in an attempt to obtain elevated permissions. Once active, ValleyRAT provides operators with extensive control over the infected machine. Kaspersky stated that the malware is capable of collecting keystrokes, capturing clipboard contents, taking screenshots, and downloading additional malicious modules. It can also mark its own process as critical, causing a blue screen error if users or administrators attempt to terminate it manually.

Kaspersky also released technical indicators associated with the campaign to assist defenders in identifying compromised systems. These include multiple malicious file hashes, command and control servers hosted at IP addresses 103.45.66.18 using ports 441, 442, and 443, along with 192.253.225.173 using ports 6666 and 8888. The researchers also identified qnwallpaper.keansoft.cn as the download source for the modified adware while meeting.tencent.com was opened as a legitimate decoy page during execution. Other artifacts include the DisableAntiSpyware registry value and installation files located under the QNWallpaper program directory. Kaspersky noted that DLL sideloading through legitimate software is a well established tactic used by Silver Fox. Approximately five weeks earlier, Cato Networks documented a campaign targeting a Japanese manufacturer in which the same threat actor abused trusted software for DLL sideloading. Researchers also observed the libcef.dll filename in a ValleyRAT loader campaign reported during 2025. Earlier this year, Kaspersky tracked the same threat actor using tax themed lures to target organizations in India and Russia, indicating continued development of the group’s delivery methods.

Although Kaspersky’s latest findings are based on a single installer submitted by one customer and do not include a confirmed victim count for this specific campaign, the company reported broader ValleyRAT activity throughout 2026. During the year, it recorded more than 100,000 detections involving ValleyRAT and related malware across more than 1,500 unique users, with most detections occurring in China and India. The company clarified that these figures represent overall ValleyRAT activity rather than infections directly linked to the QN Wallpaper campaign. Kaspersky also encouraged organizations to establish clear policies governing the use of third party software on corporate devices while increasing employee awareness of software related security risks. For individual users, the company reiterated that software with an uncertain reputation should be avoided and should never be added to antivirus or endpoint security exclusion lists, as trusted applications can sometimes be used to conceal sophisticated malware capable of compromising sensitive information and providing persistent access to attackers.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img