Kaspersky says a group tracked as Silver Fox is distributing the ValleyRAT backdoor inside QN Wallpaper, a legitimate Chinese desktop tool whose signed executable keeps the malware running under a trusted process.
The disguise leans on a habit defenders see often: users add adware they consider harmless to antivirus exclusions. QN Wallpaper is genuine adware in its unmodified form, bundling partner apps and showing banners, which makes the trust easy to abuse.
The infection chain uses DLL sideloading. The installer unpacks a modified copy of the app and runs its signed QnWallpaper.exe binary, which loads a malicious libcef.dll planted in the same directory. Because the library executes inside a signed process, controls that trust the signature never flag it.
Before the adware component starts, the installer disables Windows Defender through the DisableAntiSpyware registry key and adds itself to autorun. If the logged-in user lacks administrator rights, the malware relaunches with runas to get them. ValleyRAT can also mark its own process as critical, so killing it triggers a blue screen of death.
The backdoor, also tracked as Winos 4.0, hands operators full control: keystroke and clipboard capture, screenshots, and delivery of additional modules. Across 2026 Kaspersky counted more than 100,000 detections of ValleyRAT and related malware affecting over 1,500 unique users, mostly in China and India.
Kaspersky said the campaign’s geography and payload point to Silver Fox, which has used signed-application DLL sideloading before, including against a Japanese manufacturer weeks earlier.
The vendor urged users to avoid software of questionable reputation and, critically, to never add such programs to security-tool exclusion lists. Organizations should set clear policy on third-party software on work devices.
