
Cybersecurity researchers at Kaspersky have uncovered a sophisticated campaign spreading the ValleyRAT backdoor across Asia by disguising the malware inside a legitimate, digitally signed adware application.
In 2026 alone, Kaspersky recorded over 100,000 detections of ValleyRAT and its associated malware, affecting more than 1,500 unique users. India and China have emerged as the primary targets of the ongoing threat.
The infection chain begins when a user downloads an installer that deploys a modified version of QN Wallpaper, a desktop wallpaper management application that functions as adware. While the original application typically delivers partner software and displays ad banners, attackers modified the program to execute a DLL sideloading attack.
By distributing a malicious dynamic-link library alongside the installer, the threat actors execute the ValleyRAT backdoor under a process signed by a legitimate developer certificate. This setup allows the payload to run covertly without triggering security alerts.
Once activated, ValleyRAT grants operators extensive spyware capabilities over infected machines. The backdoor can execute several malicious functions, including:
- Capturing user keystrokes and reading clipboard contents
- Taking system screenshots
- Rebooting or shutting down the host computer
- Delivering additional malicious modules directly to the device
Kaspersky researchers attributed the campaign with high confidence to SilverFox, a known threat actor operating across multiple countries for cyberespionage and financial gain.
“ValleyRAT is a highly sophisticated backdoor that covertly performs spyware functions, putting sensitive data belonging to both individual users and organizations at risk. Normally these kinds of attacks rely on the fact that sometimes legitimate applications do not verify the libraries loaded into their address space. This allows attackers to replace a legitimate library with a malicious one bearing the same name, which the trusted application then loads without raising suspicion. As a result, the installation often goes unnoticed. Users often allow the installation of potentially unwanted software or adware on their devices, but this is one of the scenarios for malware to enter their computers, as our research proves. Therefore, we do not recommend ignoring antivirus messages about unwanted or adware,” says Vasily Kolesnikov, cybersecurity expert at Kaspersky.
Kaspersky advises individual users to take immediate steps to protect their devices from ValleyRAT:
- Do not install applications from untrusted or questionable sources.
- Avoid adding unfamiliar software to security-tool exclusion lists under any circumstances.
- Never disable antivirus or security tools to complete a software installation.
- Exercise caution whenever downloading software from the internet.
For enterprise environments, security teams should implement structured mitigation strategies:
- Establish clear corporate guidelines regarding the installation of third-party software on work devices.
- Train staff on emerging threats and promote safe software downloading practices.
- Deploy human-led detection capabilities, such as Managed Detection and Response (MDR) solutions, to maintain 24/7 monitoring and rapid incident response against advanced attacks.
- Continuously monitor corporate credentials across open and dark web sources to detect compromised accounts before they serve as entry points for broader network intrusions.
Read the full report on Securelist.com







Leave a Reply