CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5393

As cited

Copy frozen at (site build).

threat intel

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Threat actor Silver Fox is distributing the ValleyRAT backdoor masked as a signed Chinese adware application called QN Wallpaper. The malware runs under a trusted process to evade detection by users who add such software to antivirus exclusion lists. Kaspersky identified the campaign and the social engineering technique exploiting legitimate exclusion workflows.

Why it matters: Organizations and endpoint users are at risk of installing backdoored adware that bypasses security controls through trusted process execution and deliberate antivirus exclusion, giving attackers persistent remote access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary