ValleyRAT Backdoor Hidden in Adware Targets China and India
Key Takeaways A new campaign is distributing ValleyRAT, a potent Windows backdoor, disguised as legitimate adware. The primary targets are users in China and India, with over 100,000 detections...
Key Takeaways
- A new campaign is distributing ValleyRAT, a potent Windows backdoor, disguised as legitimate adware.
- The primary targets are users in China and India, with over 100,000 detections impacting 1,500+ unique users in 2026.
- The threat actors, likely the group known as Silver Fox, employ DLL sideloading and manipulate legitimate applications to achieve persistence and evade detection.
- ValleyRAT enables extensive surveillance, including keylogging, screenshot capture, and data exfiltration, along with remote control capabilities.
- Mitigation requires vigilance against suspicious software downloads, strong endpoint security, and proactive network monitoring for known Indicators of Compromise.
Cybersecurity researchers have uncovered a sophisticated campaign leveraging seemingly innocuous adware to deploy ValleyRAT, a powerful Windows backdoor. This operation primarily targets users in China and India, transforming programs designed for displaying advertisements into tools for espionage, data theft, and further malware distribution.
The initial installer exhibits polymorphic behavior, altering its visible function based on its filename. Depending on the variant, it might install a collaboration application, a web browser, or redirect to a meeting download page. These decoy actions are crucial for keeping the victim engaged while the malicious components are silently deployed onto the system. Researchers at Securelist said in a report that they identified this activity after an adware sample generated unusual network traffic. They noted that the advertising functionality of the observed adware was completely non-operational.
Instead of displaying ads, the compromised software initiated a covert infection chain, ultimately leading to the execution of ValleyRAT via a modified wallpaper management application. The extensive reach of this campaign underscores its significance. In 2026 alone, researchers documented over 100,000 detections of ValleyRAT and associated malware, affecting more than 1,500 distinct users, predominantly in China and India. Investigators attribute this activity to the threat actor group known as Silver Fox. For a deeper dive into the technical analysis, refer to the detailed report from Securelist.
Hackers Hide ValleyRAT Backdoor Inside Adware
The attack chain commences with an installer file, often named something like FS_SETUP_DD_173.exe or FS_SETUP_GG_173.exe. Regardless of the decoy application it purports to install, the primary objective is to deploy a tampered version of QN Wallpaper and configure it for automatic startup upon system boot.
This modified package exploits a technique known as DLL sideloading, a common Windows vulnerability where an application loads a legitimate supporting Dynamic Link Library (DLL) from its local directory. In this instance, QnWallpaper.exe and QnwPlayer.exe are tricked into loading a malicious libcef.dll. This allows the attackers’ code to execute within the context of what appears to be a legitimate application, making detection more challenging. This method mirrors other Silver Fox trusted software attacks.
Beyond the DLL sideloading, the installer attempts to disable Microsoft Defender by modifying the DisableAntiSpyware registry key. Malicious components are strategically placed within the Program Files directory, co-located with the wallpaper files and hidden backdoor elements. After the initial reboot, the rogue library ensures QnWallpaper.exe remains active by establishing a file association and placing a corresponding file in the Startup folder. The malware also checks for administrator privileges and attempts to elevate its own permissions if necessary, amplifying the potential damage a threat actor could inflict.
The ValleyRAT payload itself is encrypted, and its configuration is intentionally written in reverse to hinder analysis. Different payloads within the campaign utilize distinct command-and-control (C2) settings. The backdoor maintains persistence by injecting code into svchost to restart itself, a method that echoes other <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/ada137b4-722b-46f6-a821-626aaed1e05f/Hackers-Hide-ValleyRAT-Backdoor-Inside-Adware-Targeting-Users-in-China-and-India.pdf?AWSAccessKeyId=ASIA2F3EMEYE72TNSESF&Signature=hAwNdaywHWBypa47rchFJ7YAtcQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEM3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIEFSyOXkCxY8Wl880ryx0sc569lO7qKmBD3X76JNDBkTAiEAlU4fZWeeZb%2BB9G8TpLyPIEpuNZ%2Bl%2BlBd4UmiKLrusSkq%2FAQIlv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDLwfQveW0SH6e%2FSNHyrQBBcBl8ZfZRZG%2Bzjl%2BQvxSNiySx0ihWyeqW11Vtiyc8nn7vJbUGEzcvzJJ7mf3LGzi%2FbCTeS52Zjt8DeOoUYIGERaHMIIVI9MsfqmvRUOlMbUCLoRyikehuuJ4lDabpYGY6jHP%2FvVGhqAjSiFXfZTnLXZA4lmtm%2B6CdeazLsX5ue7gz5jrWWXRsZYBH7c8Vx6kBwR%2FAFusm%2BV0cw738hqMWheF9OFqaBOR1w4sACPY8PACd6NJpGI%2FItvnwy4Tt%2FEX%2Bk09H3L4aPcWeB4nEOnequE53pgUzd%2Br3o665SRPIFC5%2FC%2BH5PDfl5XNJukd1K0%2FGbgK1ccnG6lvPmaFKS7AP0IctDVdWH9mCdkUQsxoR3Ep7pWPDSC4Ge%2B0%2BAeZl9jy46GD7xXHgtGpJCJzIpL0cRbNjLOp2vdKVEEmfKSo7LKvfhH57Lxd61TwNqLlI8B0hWF3PQs5cOnfEoIPuuD0TxV%2BI9VRGqIjSvRVyU4ABP7CEGrkUM117rBRiiFMHYz3GvcST8v8wu%2B%2Fb6xada8gjTjF52BhvLATpD52RFC0HEWzfE0rbp1oJjlxI4cJyrX79oxJf2UfIHqBKrpGgq2vImBlnBMbH5GEGRPu0JJm2SIKov6r93zFl0XllIOgq4YtOskEcAFSRyxhSxni8HDLbA7Z5gkuoeYYeOF0%2B16WebpVF0Rhyp6eNmYMSnhEZZRF5o3ExRCnPWVE8cOoyri2dBix3yH8DrzPC5u3ko5XJWpuszzx4eQmxZvxAkhm0%2BxdTk3VROVkLNpgOB5ycLxFbYwmffV1AY6mAFArTKiczhQrn2kYDxW2SffhNQiT2tyTuWDOWJtzxc005tIeO5cUhMpzDdNHzCOv2aUT%2FqRUYKu4uWF%2FuqXYEuwbdTe2YZFVz1
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.