Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
ValleyRAT Backdoor Hidden in Adware Targets China and India
August 31, 2026
EU Designates ChatGPT a Very Large Online Platform After Reaching 45 Million Users
August 31, 2026
Brave Launches Email Aliases for Enhanced User Privacy
August 31, 2026
Home/Threats/ValleyRAT Backdoor Hidden in Adware Targets China and India
Threats

ValleyRAT Backdoor Hidden in Adware Targets China and India

Key Takeaways A new campaign is distributing ValleyRAT, a potent Windows backdoor, disguised as legitimate adware. The primary targets are users in China and India, with over 100,000 detections...

Sarah simpson
Sarah simpson
August 31, 2026 3 Min Read
2 0

Key Takeaways

  • A new campaign is distributing ValleyRAT, a potent Windows backdoor, disguised as legitimate adware.
  • The primary targets are users in China and India, with over 100,000 detections impacting 1,500+ unique users in 2026.
  • The threat actors, likely the group known as Silver Fox, employ DLL sideloading and manipulate legitimate applications to achieve persistence and evade detection.
  • ValleyRAT enables extensive surveillance, including keylogging, screenshot capture, and data exfiltration, along with remote control capabilities.
  • Mitigation requires vigilance against suspicious software downloads, strong endpoint security, and proactive network monitoring for known Indicators of Compromise.

Cybersecurity researchers have uncovered a sophisticated campaign leveraging seemingly innocuous adware to deploy ValleyRAT, a powerful Windows backdoor. This operation primarily targets users in China and India, transforming programs designed for displaying advertisements into tools for espionage, data theft, and further malware distribution.

The initial installer exhibits polymorphic behavior, altering its visible function based on its filename. Depending on the variant, it might install a collaboration application, a web browser, or redirect to a meeting download page. These decoy actions are crucial for keeping the victim engaged while the malicious components are silently deployed onto the system. Researchers at Securelist said in a report that they identified this activity after an adware sample generated unusual network traffic. They noted that the advertising functionality of the observed adware was completely non-operational.

Instead of displaying ads, the compromised software initiated a covert infection chain, ultimately leading to the execution of ValleyRAT via a modified wallpaper management application. The extensive reach of this campaign underscores its significance. In 2026 alone, researchers documented over 100,000 detections of ValleyRAT and associated malware, affecting more than 1,500 distinct users, predominantly in China and India. Investigators attribute this activity to the threat actor group known as Silver Fox. For a deeper dive into the technical analysis, refer to the detailed report from Securelist.

Hackers Hide ValleyRAT Backdoor Inside Adware

The attack chain commences with an installer file, often named something like FS_SETUP_DD_173.exe or FS_SETUP_GG_173.exe. Regardless of the decoy application it purports to install, the primary objective is to deploy a tampered version of QN Wallpaper and configure it for automatic startup upon system boot.

This modified package exploits a technique known as DLL sideloading, a common Windows vulnerability where an application loads a legitimate supporting Dynamic Link Library (DLL) from its local directory. In this instance, QnWallpaper.exe and QnwPlayer.exe are tricked into loading a malicious libcef.dll. This allows the attackers’ code to execute within the context of what appears to be a legitimate application, making detection more challenging. This method mirrors other Silver Fox trusted software attacks.

Beyond the DLL sideloading, the installer attempts to disable Microsoft Defender by modifying the DisableAntiSpyware registry key. Malicious components are strategically placed within the Program Files directory, co-located with the wallpaper files and hidden backdoor elements. After the initial reboot, the rogue library ensures QnWallpaper.exe remains active by establishing a file association and placing a corresponding file in the Startup folder. The malware also checks for administrator privileges and attempts to elevate its own permissions if necessary, amplifying the potential damage a threat actor could inflict.

The ValleyRAT payload itself is encrypted, and its configuration is intentionally written in reverse to hinder analysis. Different payloads within the campaign utilize distinct command-and-control (C2) settings. The backdoor maintains persistence by injecting code into svchost to restart itself, a method that echoes other <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ada137b4-722b-46f6-a821-626aaed1e05f/Hackers-Hide-ValleyRAT-Backdoor-Inside-Adware-Targeting-Users-in-China-and-India.pdf?AWSAccessKeyId=ASIA2F3EMEYE72TNSESF&Signature=hAwNdaywHWBypa47rchFJ7YAtcQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEM3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIEFSyOXkCxY8Wl880ryx0sc569lO7qKmBD3X76JNDBkTAiEAlU4fZWeeZb%2BB9G8TpLyPIEpuNZ%2Bl%2BlBd4UmiKLrusSkq%2FAQIlv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDLwfQveW0SH6e%2FSNHyrQBBcBl8ZfZRZG%2Bzjl%2BQvxSNiySx0ihWyeqW11Vtiyc8nn7vJbUGEzcvzJJ7mf3LGzi%2FbCTeS52Zjt8DeOoUYIGERaHMIIVI9MsfqmvRUOlMbUCLoRyikehuuJ4lDabpYGY6jHP%2FvVGhqAjSiFXfZTnLXZA4lmtm%2B6CdeazLsX5ue7gz5jrWWXRsZYBH7c8Vx6kBwR%2FAFusm%2BV0cw738hqMWheF9OFqaBOR1w4sACPY8PACd6NJpGI%2FItvnwy4Tt%2FEX%2Bk09H3L4aPcWeB4nEOnequE53pgUzd%2Br3o665SRPIFC5%2FC%2BH5PDfl5XNJukd1K0%2FGbgK1ccnG6lvPmaFKS7AP0IctDVdWH9mCdkUQsxoR3Ep7pWPDSC4Ge%2B0%2BAeZl9jy46GD7xXHgtGpJCJzIpL0cRbNjLOp2vdKVEEmfKSo7LKvfhH57Lxd61TwNqLlI8B0hWF3PQs5cOnfEoIPuuD0TxV%2BI9VRGqIjSvRVyU4ABP7CEGrkUM117rBRiiFMHYz3GvcST8v8wu%2B%2Fb6xada8gjTjF52BhvLATpD52RFC0HEWzfE0rbp1oJjlxI4cJyrX79oxJf2UfIHqBKrpGgq2vImBlnBMbH5GEGRPu0JJm2SIKov6r93zFl0XllIOgq4YtOskEcAFSRyxhSxni8HDLbA7Z5gkuoeYYeOF0%2B16WebpVF0Rhyp6eNmYMSnhEZZRF5o3ExRCnPWVE8cOoyri2dBix3yH8DrzPC5u3ko5XJWpuszzx4eQmxZvxAkhm0%2BxdTk3VROVkLNpgOB5ycLxFbYwmffV1AY6mAFArTKiczhQrn2kYDxW2SffhNQiT2tyTuWDOWJtzxc005tIeO5cUhMpzDdNHzCOv2aUT%2FqRUYKu4uWF%2FuqXYEuwbdTe2YZFVz1

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityHackerMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

EU Designates ChatGPT a Very Large Online Platform After Reaching 45 Million Users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ethereum Blockchain Used to Steal Credit Card Data From Shoppers
August 31, 2026
Critical Vulnerability in npm Package ‘netmask’ Exposes Credentials
August 31, 2026
Microsoft Defender Bug Triggers False “Antivirus Off” Alerts
August 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us