As cited
Copy frozen at (site build).
threat intel
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Threat actor Silver Fox is distributing the ValleyRAT backdoor masked as a signed Chinese adware application called QN Wallpaper. The malware runs under a trusted process to evade detection by users who add such software to antivirus exclusion lists. Kaspersky identified the campaign and the social engineering technique exploiting legitimate exclusion workflows.
Why it matters: Organizations and endpoint users are at risk of installing backdoored adware that bypasses security controls through trusted process execution and deliberate antivirus exclusion, giving attackers persistent remote access.
- Source published
- First seen by Cybersecurity Tracker