CyberSecurity News
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
AI summary
The Silver Fox threat actor is distributing the ValleyRAT backdoor by disguising it as a legitimate Chinese adware application. This malware is hidden within a signed version of QN Wallpaper, a genuine Chinese desktop-wallpaper tool. The attackers are able to evade detection by running the malware under a trusted process, which can slip past users who exempt such software from antivirus scans. Users may inadvertently aid the attackers by adding the adware to their antivirus exclusions, unaware that it contains the ValleyRAT backdoor. This tactic allows the malware to operate without being detected by security software.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

