ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
ID: b6786971-5669-53d2-80ea-7923c38d7045
STIX ID: report--b6786971-5669-53d2-80ea-7923c38d7045
Feed Name: The Hacker News
Threat Score
**Silver Fox** distributed the **ValleyRAT** backdoor hidden inside a modified, signed QN Wallpaper adware installer that uses DLL sideloading (malicious libcef.dll) to run inside a trusted process, disables Windows Defender, achieves persistence and privilege escalation, and can mark itself critical to trigger a BSOD if terminated; Kaspersky published MD5 hashes, C2 IPs/ports, domains and host artifacts and urged caution around third-party software and antivirus exclusion lists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
