Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, silver-fox, valleyrat, winos, adware, dll-sideloading, kaspersky, malware] ยท confidence: medium ยท severity: medium ยท affected_sectors: [Global] ยท au_impact: false

Silver Fox Distributes ValleyRAT Inside Signed Chinese Adware

Summary

Kaspersky documented the Silver Fox group distributing the ValleyRAT backdoor disguised as QN Wallpaper, a genuine signed Chinese desktop-wallpaper adware tool, in August 2026.

Details

The disguise relies on DLL sideloading: the installer unpacks a modified copy of QN Wallpaper and runs its signed QnWallpaper.exe, which loads a malicious libcef.dll planted in the same directory โ€” executing the backdoor inside a legitimately signed process. Before the adware runs, the installer disables Windows Defender via the DisableAntiSpyware registry key and registers the program in autorun; without administrator rights it relaunches itself with runas. ValleyRAT (tracked as Winos 4.0) collects keystrokes, clipboard contents and screenshots, delivers further modules, and can flag its own process as critical so terminating it triggers a blue screen.

Assessment

This is a clear example of adware and affiliate networks being weaponised beyond their apparent nuisance value. Across 2026 Kaspersky recorded more than 100,000 ValleyRAT detections affecting over 1,500 unique users, mostly in China and India. Users should avoid software of questionable reputation and, critically, never add such software to security-solution exclusion lists.