"This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear," Kaspersky said in its analysis.
Silver Fox uses QN Wallpaper to deploy the ValleyRAT backdoor
Russian vendor Kaspersky reported that the threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application. The attackers built the disguise around QN Wallpaper, a bona fide Chinese desktop‑wallpaper tool that, in its unmodified form, acts as adware—bundling partner apps and displaying ad banners. When installed in its malicious form, ValleyRAT (also tracked as Winos 4.0) hands an operator full control of the compromised machine, including data collection and the delivery of additional modules.
DLL sideloading through a signed QnWallpaper.exe and libcef.dll
Kaspersky mapped the infection chain to DLL sideloading. The submitted installer unpacks a modified copy of QN Wallpaper and runs the signed executable QnWallpaper.exe; that signed process then loads a malicious libcef.dll planted in the same directory. Running the backdoor inside a legitimately signed process lets the payload operate without triggering controls that trust the executable's signature.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coveragePersistence, privilege escalation, and anti‑tamper tactics
The installer takes immediate steps to disable defenses and remain active. Before the adware component starts, it sets the DisableAntiSpyware registry key to switch off Windows Defender and adds the program to autorun entries. If the logged‑in user lacks administrator rights, the malware relaunches itself with runas to acquire them. ValleyRAT can also flag its own process as critical so that any attempt to terminate it triggers a blue screen of death, Kaspersky reported.
Indicators of compromise (IoCs) and observable artifacts
- MD5 hashes (as provided by Kaspersky): c24e99f9437feacaa63766a3cde3fe3d (the submitted installer); 07ddbbe2c71c45577a7a4fbcdba0df91 (the malicious libcef.dll); and 8a626d844943da3456b044f38deae3a2.
- Command‑and‑control servers: 103.45.66.18 on ports 441, 442 and 443; and 192.253.225.173 on ports 6666 and 8888.
- Domains in the chain: qnwallpaper[.]keansoft[.]cn (the adware's download site) and meeting[.]tencent[.]com (a legitimate page opened as a decoy).
- Host artifacts and paths: the presence of the DisableAntiSpyware registry value and the install directory C:\Program Files\QNWallpaper\5.4.0.1662\.
Context from prior activity: Silver Fox, libcef.dll, and ValleyRAT
Kaspersky noted that DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit. Cato Networks documented a campaign against a Japanese manufacturer about five weeks earlier that the vendor described as the group's "newly observed abuse of legitimate applications for DLL sideloading." The same libcef.dll filename had also featured in a 2025 ValleyRAT loader. Kaspersky itself linked Silver Fox to an earlier tax‑themed campaign against organizations in India and Russia.
What this means for technologists, procurement teams, and individual users
- Technologists and security teams: watch for DLL sideloading in signed binaries—especially QnWallpaper.exe running suspicious libcef.dll libraries—and monitor the DisableAntiSpyware key, autorun entries, and the C:\Program Files\QNWallpaper\5.4.0.1662\ path listed by Kaspersky.
- Procurement and enterprise IT: set clear policies on third‑party software on work devices and restrict or vet adware and affiliate‑bundled applications before approving them for corporate endpoints, as Kaspersky urged.
- Individual users: avoid installing software with a questionable reputation, and never add such programs to security‑solution exclusion lists—the specific safeguard Kaspersky called out in its recommendation.
Kaspersky based its account on a single installer submitted by a customer and cautioned that the adware's advertising features remain inert while the infection chain runs; the vendor did not attach a victim count to this adware route. Across 2026 Kaspersky recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users—mostly in China and India—a figure that spans all of the year's ValleyRAT activity rather than this campaign alone.
The verifiable, immediate takeaway is straightforward: this campaign shows how a signed, seemingly legitimate adware package can be turned into a covert loader. Kaspersky's guidance is equally specific—treat third‑party desktop utilities with caution, keep them off exclusion lists, and apply rigorous oversight to any software that arrives through ad networks or affiliate channels.
Original report: https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html




