HackMyIP
← Back to News
2026-08-31 The Hacker News

Silver Fox Hides ValleyRAT Backdoor in Signed Chinese Adware to Bypass Antivirus

MalwareThreat IntelAPT

Threat actor Silver Fox has been spotted distributing the ValleyRAT backdoor (also tracked as Winos 4.0) disguised as QN Wallpaper, a legitimate but ad-supported Chinese desktop wallpaper application. According to Kaspersky, the attackers bundle the signed QnWallpaper.exe installer with a malicious libcef.dll planted in the same directory, exploiting DLL sideloading to execute the backdoor inside a trusted, digitally signed process. This technique lets the malware bypass security tools when users add the seemingly benign adware to their antivirus exclusions, handing operators full remote control over the compromised endpoint.

The installer takes several steps to ensure persistence and evade detection before the adware component even launches. It disables Windows Defender via the DisableAntiSpyware registry key, adds the program to the system's autorun entries, and relaunches itself with runas to escalate privileges if the logged-in user lacks administrator rights. ValleyRAT can also flag its process as critical, causing a blue screen of death if a user attempts to terminate it. The backdoor is capable of capturing keystrokes, clipboard contents, and screenshots, as well as delivering additional malicious modules on demand.

Kaspersky published several indicators of compromise, including MD5 hashes for the installer (c24e99f9437feacaa63766a3cde3fe3d) and the malicious libcef.dll (07ddbbe2c71c45577a7a4fbcdba0df91), alongside command-and-control servers at 103.45.66.18 and 192.253.225.173. The abuse domain qnwallpaper[.]keansoft[.]cn serves as the adware's download site, while meeting[.]tencent[.]com is opened as a decoy page. Researchers noted that this libcef.dll sideloading pattern was previously documented in a 2025 ValleyRAT loader and in a recent campaign against a Japanese manufacturer, confirming it as a recurring tactic in Silver Fox's playbook. Defenders can validate exposure by running a quick port scanner against the listed C2 IPs, checking domain ownership with a WHOIS lookup on qnwallpaper[.]keansoft[.]cn, and reviewing endpoints for the C:\Program Files\QNWallpaper\5.4.0.1662\ install path. Users should avoid adding low-reputation software to antivirus exclusion lists and verify software signatures before installation.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →