Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to Slip Past AV Exclusions

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-09-01 T 03:29:31 Z | [ 1 MIN READ ]
Silver Fox Unleashes ValleyRAT backdoor via Signed Chinese Adware to Slip Past AV Exclusions
1 Min Read
Share

ValleyRAT backdoor Disguised as Signed Chinese Adware

The cyber‑crime crew identified as Silver Fox has begun packaging the ValleyRAT backdoor inside a legitimate‑looking Chinese wallpaper utility called QN Wallpaper. By signing the payload, the malicious code runs under a trusted process, fooling users who add the program to their antivirus exclusions. Kaspersky’s threat intel team reported that the adware carries a valid digital certificate, allowing it to bypass default security heuristics.

‘The attacker’s strategy relies on user trust in signed software,’ a Kaspersky analyst told Reuters.

Once the counterfeit QN Wallpaper is installed, the hidden backdoor establishes a covert channel to command‑and‑control servers, enabling data exfiltration and further payload delivery. Security researchers warn that the practice could increase infection rates by ↓ 30% among enterprises that whitelist the app. Defenders are urged to block unsigned execution paths and to verify code signatures against known benign hashes. For a deeper technical breakdown, see the analysis on Bloomberg.


Intel provided by Kaelen Frost (Lead Cybersecurity Analyst).

Global Data Feed

More from this Intel

Claude AI hack exposes 1.8 M Android apps to espionage

Claude AI hack exposes 1.8 M Android apps to espionage

Sep 12, 2026
JFrog Artifactory flaws exploited for admin takeover and backdoor insertion

JFrog Artifactory flaws exploited for admin takeover and backdoor insertion

Sep 11, 2026
Android malware Mantax Otax: Hybrid ransomware‑spyware strikes devices

Android malware Mantax Otax: Hybrid ransomware‑spyware strikes devices

Sep 11, 2026
News

Exposed Plex Servers Pose Massive Cyber Risk as 36,000 Remain...

Sep 09, 2026
TeamPCP Hackers Arrested in Australia: Two Cybercriminals Nabbed

TeamPCP Hackers Arrested in Australia: Two Cybercriminals Nabbed

Sep 08, 2026
AI Hidden Vulnerabilities Vanish: Are Software Vendors Keeping Pace?

AI Hidden Vulnerabilities Vanish: Are Software Vendors Keeping Pace?

Sep 07, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.