ValleyRAT backdoor concealed in signed adware
🛡️ Kaspersky attributes a campaign to Silver Fox that hides the ValleyRAT backdoor inside a legitimately signed Chinese adware installer, QN Wallpaper. The attackers use DLL sideloading to run a malicious libcef.dll within the signed QnWallpaper.exe, disable Windows Defender, add autorun entries, and escalate privileges with runas. ValleyRAT can steal keystrokes and screenshots, mark its process as critical to induce BSOD on termination, and contacts several C2 servers and domains.
