ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Summary

A threat actor named Silver Fox is distributing a backdoor called ValleyRAT. This malware is disguised as a signed Chinese adware application, specifically a legitimate desktop wallpaper tool called QN Wallpaper. By masquerading as trusted software, the attackers aim to bypass antivirus detections, particularly when users have added such applications to their antivirus exclusion lists.

IFF Assessment

FOE

The discovery of a new backdoor and its sophisticated evasion techniques poses a significant threat to defenders.

Defender Context

Defenders should be aware of the evolving tactics used by threat actors to bypass security controls, such as disguising malware as signed adware. This highlights the importance of vigilant monitoring, understanding user behavior regarding antivirus exclusions, and implementing layered security approaches that go beyond signature-based detection.

Read Full Story →