CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

August 31, 2026

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions Swati KhandelwalAug 31, 2026Malware / Endpoint Security The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack's geography and payload point to Silver Fox as…