<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl" -->

---
title: ValleyRAT is spreading disguised as adware | daily.dev
description: Researchers analyzed a malicious installer distributing the ValleyRAT backdoor disguised as legitimate adware called QN Wallpaper. The installer performs decoy...
canonical: https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: ValleyRAT is spreading disguised as adware | daily.dev
og:description: Researchers analyzed a malicious installer distributing the ValleyRAT backdoor disguised as legitimate adware called QN Wallpaper. The installer performs decoy...
og:url: https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl
og:image: https://api.daily.dev/og/posts/obIk8vDbL.png
og:image:alt: ValleyRAT is spreading disguised as adware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ValleyRAT is spreading disguised as adware

**[Securelist](https://daily.dev/sources/securelist)** · 9 min read · 0 upvotes · 0 comments

## Summary

Researchers analyzed a malicious installer distributing the ValleyRAT backdoor disguised as legitimate adware called QN Wallpaper. The installer performs decoy actions (installing DingTalk, Chrome, or opening a Tencent Meeting link) while covertly deploying a modified, signed version of QN Wallpaper that uses DLL sideloading via a malicious libcef.dll to load the AES-encrypted ValleyRAT payload. The backdoor disables Windows Defender, escalates privileges, protects its process via svchost injection and critical-process marking, and includes keylogging, clipboard capture, screenshot, and module-download capabilities. Over the course of the year, more than 100,000 detections affecting over 1,500 unique users were recorded, mostly in China and India, with attribution pointing to the Silver Fox threat group motivated by espionage and financial gain.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/valleyrat-backdoor-adware/121175>

## Questions this post answers

### How does the ValleyRAT backdoor get loaded through DLL sideloading in the QN Wallpaper adware attack?

A trojanized installer drops a modified, signed QN Wallpaper application along with a malicious libcef.dll. When QnWallpaper.exe or QnwPlayer.exe launches, it loads libcef.dll as a dependency, triggering malicious code in DllMain that decrypts an AES-encrypted payload (from a PeLoader file or DLL resources) containing ValleyRAT, then hands control to it via DllMain.

_Security teams tracking DLL sideloading techniques like this can follow related malware writeups on daily.dev._

### What data does the ValleyRAT backdoor collect from infected Windows machines?

ValleyRAT logs keystrokes and the currently focused window using DirectInput8, captures clipboard contents, and gathers system details including hostname, IP addresses, user idle time, Windows version, CPU core count, free disk space, graphics adapter, and language settings. It can also take screenshots, wipe logs, reboot or shut down the machine, and download additional modules on command.

_Developers building endpoint defenses can track backdoor capabilities like these on daily.dev._

### Which threat group is behind the ValleyRAT backdoor campaign disguised as adware?

Silver Fox, a known operator of the ValleyRAT malware family, is the likely group behind this campaign based on attack geography and malware use. Over a year, the backdoor and associated malware were detected more than 100,000 times affecting over 1,500 unique users, primarily in China and India, with motives spanning cyberespionage and financial gain.

_Anyone tracking threat actor campaigns like Silver Fox can follow analysis like this on daily.dev._

## Similar posts on daily.dev

- [Fake Huorong security site infects users with ValleyRAT](https://daily.dev/posts/fake-huorong-security-site-infects-users-with-valleyrat-wjalu7j3l) · Security Boulevard · 1 upvotes · 0 comments
- [Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China](https://daily.dev/posts/silver-fox-uses-fake-microsoft-teams-installer-to-spread-valleyrat-malware-in-china-odxv7rs2i) · The Hacker News · 0 upvotes · 0 comments
- [SilverFox Hackers Use Go RAT, AV Killer, and Kernel Rootkit in ValleyRAT Campaign](https://daily.dev/posts/silverfox-hackers-use-go-rat-av-killer-and-kernel-rootkit-in-valleyrat-campaign-8mnjmf0s7) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"ValleyRAT is spreading disguised as adware","url":"https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl"},"datePublished":"2026-08-31T10:04:09.664Z","dateModified":"2026-08-31T10:04:42.135Z","description":"Researchers analyzed a malicious installer distributing the ValleyRAT backdoor disguised as legitimate adware called QN Wallpaper. The installer performs decoy...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6a9b91c7d505e98598619590e618a4c9?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/6a9b91c7d505e98598619590e618a4c9?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Securelist","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Securelist","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/e4b9f556af7a4e74a179787362dd5b07","url":"https://daily.dev/sources/securelist"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Securelist","item":"https://daily.dev/sources/securelist"},{"@type":"ListItem","position":3,"name":"ValleyRAT is spreading disguised as adware"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/valleyrat-is-spreading-disguised-as-adware-obik8vdbl#faq","mainEntity":[{"@type":"Question","name":"How does the ValleyRAT backdoor get loaded through DLL sideloading in the QN Wallpaper adware attack?","acceptedAnswer":{"@type":"Answer","text":"A trojanized installer drops a modified, signed QN Wallpaper application along with a malicious libcef.dll. When QnWallpaper.exe or QnwPlayer.exe launches, it loads libcef.dll as a dependency, triggering malicious code in DllMain that decrypts an AES-encrypted payload (from a PeLoader file or DLL resources) containing ValleyRAT, then hands control to it via DllMain. Security teams tracking DLL sideloading techniques like this can follow related malware writeups on daily.dev."}},{"@type":"Question","name":"What data does the ValleyRAT backdoor collect from infected Windows machines?","acceptedAnswer":{"@type":"Answer","text":"ValleyRAT logs keystrokes and the currently focused window using DirectInput8, captures clipboard contents, and gathers system details including hostname, IP addresses, user idle time, Windows version, CPU core count, free disk space, graphics adapter, and language settings. It can also take screenshots, wipe logs, reboot or shut down the machine, and download additional modules on command. Developers building endpoint defenses can track backdoor capabilities like these on daily.dev."}},{"@type":"Question","name":"Which threat group is behind the ValleyRAT backdoor campaign disguised as adware?","acceptedAnswer":{"@type":"Answer","text":"Silver Fox, a known operator of the ValleyRAT malware family, is the likely group behind this campaign based on attack geography and malware use. Over a year, the backdoor and associated malware were detected more than 100,000 times affecting over 1,500 unique users, primarily in China and India, with motives spanning cyberespionage and financial gain. Anyone tracking threat actor campaigns like Silver Fox can follow analysis like this on daily.dev."}}]}
```

