<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions]]></title><description><![CDATA[<p dir="auto">Silver Fox, the threat actor behind multiple recent campaigns, has shifted tactics by distributing the <strong>ValleyRAT</strong> backdoor inside a signed Chinese adware application. According to Kaspersky, the malware is being executed under the guise of a legitimate process to exploit a common user habit: adding known adware to antivirus exclusions.</p>
<p dir="auto">The attackers built their disguise around <em>QN Wallpaper</em>, a real desktop-wallpaper tool. Because the application is signed, it appears trustworthy, and users who may have previously whitelisted such software to reduce alerts inadvertently provide a safe harbor for the malware to operate.</p>
<p dir="auto">Key technical details from the analysis:</p>
<ul>
<li>ValleyRAT is delivered via a loader that mimics the legitimate QN Wallpaper executable.</li>
<li>The backdoor establishes persistence and can capture keystrokes, take screenshots, and download additional payloads.</li>
<li>The signed binary allows the malicious code to run under a trusted process name, bypassing security checks that rely on reputation.</li>
</ul>
<p dir="auto">While the campaign appears targeted at Chinese-speaking users, the technique of abusing signed adware is broadly applicable. Organizations should review their antivirus exclusion lists and ensure that no unfamiliar or adware-related entries persist.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given that this tactic relies on users manually adding adware to exclusions, how is your organization auditing existing exclusion entries to prevent similar abuse?</p>
]]></description><link>https://xploitlk.com/topic/166/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 14:21:55 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/166.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 31 Aug 2026 12:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>