Silver Fox Deploys ValleyRAT Backdoor via Signed Chinese Adware
Attackers weaponize a legitimate wallpaper tool to trick users into whitelisting a backdoor in antivirus settings.
The threat actor known as Silver Fox is distributing the ValleyRAT backdoor by disguising it as a signed Chinese adware application. This campaign leverages a genuine desktop-wallpaper tool to bypass security software and maintain persistence on infected systems.
According to reports from the Russian cybersecurity vendor Kaspersky, the attackers utilize a legitimate, digitally signed Chinese adware tool called QN Wallpaper. The operation employs a technique known as DLL sideloading, specifically using a malicious libcef.dll file that runs within the trusted QN Wallpaper process. By operating under the umbrella of a signed application, the ValleyRAT backdoor—also referred to as Winos 4.0—can slip past many standard security detections.
The Psychology of the Bypass
This strategy targets a specific vulnerability in user behavior rather than a software flaw. Threat actors frequently employ "living-off-the-land" techniques, using legitimate software to blend into a system's normal operations. In this instance, the attackers rely on the fact that users often perceive wallpaper tools as harmless. When such software triggers a false positive in an antivirus program, users are frequently inclined to manually add the application to their antivirus exclusions list to stop the alerts.
Why It Matters
This campaign highlights a dangerous social engineering loophole where the trust in a digitally signed application is weaponized. By tricking the user into creating a manual security override, the attackers effectively create a permanent blind spot in the system's defenses. Once the user whitelists the signed adware, the embedded ValleyRAT backdoor can operate without triggering further alerts, allowing the attackers to maintain long-term access to the compromised machine.
What's Next
Security professionals are advised to monitor for the presence of unauthorized DLLs within legitimate application directories, particularly those associated with QN Wallpaper. As Silver Fox continues to refine its delivery methods, the industry must address the risk posed by user-driven antivirus exclusions. Further analysis is expected to determine the full scale of the campaign and the specific targets of the ValleyRAT backdoor.