The record
Written from the 1 report below. Nothing here is unsourced.
- The hacking group Silver Fox is distributing a backdoor called ValleyRAT disguised as a genuine, digitally signed Chinese wallpaper tool, QN Wallpaper, according to Kaspersky.
- The malware uses DLL sideloading to run inside a trusted process, disables Windows Defender, and can steal keystrokes, clipboard data, and screenshots while giving attackers full control of infected machines.
- The campaign matters because it shows how low-reputation adware can be weaponized, especially when users add such software to their antivirus exclusion lists.
- Kaspersky recorded over 100,000 ValleyRAT detections in 2026 across more than 1,500 users, mostly in China and India.
What to watch next
- Further reports of victims or spread via the QN Wallpaper disguise, which Kaspersky's account is based on only a single submitted installer
- New indicators of compromise or updated Kaspersky guidance as its analysis is still evolving
- Renewed scrutiny of adware and third-party software policies in organizations, as Kaspersky urged
Coverage1
1 report
English national1
All filed from India
Named China · India · Russia · QN Wallpaper · Win 10 · Cato Networks · Kaspersky · Silver Fox · ValleyRAT
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
