ValleyRAT is spreading disguised as adware
Attackers are distributing the ValleyRAT backdoor disguised as legitimate Chinese adware called QN Wallpaper. The malicious installer deploys a modified version of the wallpaper management tool and uses DLL sideloading techniques to execute malicious code under a signed process. ValleyRAT is a sophisticated backdoor capable of keylogging, clipboard monitoring, screenshot capture, and delivering additional modules. The campaign has affected over 1,500 unique users, primarily in China and India, with more than 100,000 detections throughout 2026. Attribution points to the Silver Fox threat group, known for operating ValleyRAT. The attackers disabled Windows Defender, established persistence mechanisms, and implemented process protection techniques including marking processes as critical to trigger system crashes if terminated.
Indicators of Compromise
- ip: 103.45.66.18
- ip: 192.253.225.173
- hash: c24e99f9437feacaa63766a3cde3fe3d
- hash: 07ddbbe2c71c45577a7a4fbcdba0df91
- hash: 8a626d844943da3456b044f38deae3a2
ValleyRAT is spreading disguised as adware
Description
Attackers are distributing the ValleyRAT backdoor disguised as legitimate Chinese adware called QN Wallpaper. The malicious installer deploys a modified version of the wallpaper management tool and uses DLL sideloading techniques to execute malicious code under a signed process. ValleyRAT is a sophisticated backdoor capable of keylogging, clipboard monitoring, screenshot capture, and delivering additional modules. The campaign has affected over 1,500 unique users, primarily in China and India, with more than 100,000 detections throughout 2026. Attribution points to the Silver Fox threat group, known for operating ValleyRAT. The attackers disabled Windows Defender, established persistence mechanisms, and implemented process protection techniques including marking processes as critical to trigger system crashes if terminated.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/valleyrat-backdoor-adware/121175/"]
- Adversary
- Void Arachne
- Pulse Id
- 6a9561756240dfd1ccd91f80
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip103.45.66.18 | — | |
ip192.253.225.173 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashc24e99f9437feacaa63766a3cde3fe3d | — | |
hash07ddbbe2c71c45577a7a4fbcdba0df91 | — | |
hash8a626d844943da3456b044f38deae3a2 | — |
Threat ID: 6a959fdfacd9273b49460441
Added to database: 08/31/2026, 15:38:07 UTC
Last updated: 09/01/2026, 02:09:00 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.