
highMalware
ValleyRAT Backdoor Disguised as Signed QN Wallpaper Adware Evades Antivirus Defenses
Kaspersky reports that the Silver Fox threat actor has been distributing the ValleyRAT backdoor by disguising it as a legitimate, signed Chinese adware application called QN Wallpaper. The malware runs under the trusted process signature, allowing it to bypass antivirus protections, particularly when users manually add such signed software to their exclusions lists. The attack leverages the trust associated with signed applications to maintain persistence and evade detection globally.
The Hacker News1 min read