Silver Fox, the threat actor behind multiple recent campaigns, has shifted tactics by distributing the ValleyRAT backdoor inside a signed Chinese adware application. According to Kaspersky, the malware is being executed under the guise of a legitimate process to exploit a common user habit: adding known adware to antivirus exclusions.
The attackers built their disguise around QN Wallpaper, a real desktop-wallpaper tool. Because the application is signed, it appears trustworthy, and users who may have previously whitelisted such software to reduce alerts inadvertently provide a safe harbor for the malware to operate.
Key technical details from the analysis:
- ValleyRAT is delivered via a loader that mimics the legitimate QN Wallpaper executable.
- The backdoor establishes persistence and can capture keystrokes, take screenshots, and download additional payloads.
- The signed binary allows the malicious code to run under a trusted process name, bypassing security checks that rely on reputation.
While the campaign appears targeted at Chinese-speaking users, the technique of abusing signed adware is broadly applicable. Organizations should review their antivirus exclusion lists and ensure that no unfamiliar or adware-related entries persist.
Source: The Hacker News
Given that this tactic relies on users manually adding adware to exclusions, how is your organization auditing existing exclusion entries to prevent similar abuse?