ValleyRAT masquerading as adware

    Date: 09/01/2026

    Severity: High

    Summary

    The ValleyRAT campaign disguises a backdoor as signed adware, abusing the legitimate QN Wallpaper application and DLL sideloading via a malicious libcef.dll to load AES-encrypted payloads in memory. The backdoor performs keylogging, credential harvesting by capturing clipboard content, screenshot capture, system reconnaissance, defense evasion, persistence, and process hollowing for additional payload execution. The campaign primarily affected users in China and India and is likely linked to the Silver Fox threat actor.  

    Indicators of Compromise (IOC) List 

    IP Address

    103.45.66.18

    192.253.225.173

    Hash

    07ddbbe2c71c45577a7a4fbcdba0df91

    8a626d844943da3456b044f38deae3a2

    c24e99f9437feacaa63766a3cde3fe3d

    9a71d6a41cd258b9e89cdc5fc224de73

    c24e99f9437feacaa63766a3cde3fe3d

    6c158c0f8e029342192d4f0d72e102b7

    48826d5ca845979d2e6ebd66dc1aae90

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("103.45.66.18","192.253.225.173") or srcipaddress IN ("103.45.66.18","192.253.225.173")

    Detection Query 2 :

    md5hash IN ("07ddbbe2c71c45577a7a4fbcdba0df91","48826d5ca845979d2e6ebd66dc1aae90","9a71d6a41cd258b9e89cdc5fc224de73","6c158c0f8e029342192d4f0d72e102b7","8a626d844943da3456b044f38deae3a2","c24e99f9437feacaa63766a3cde3fe3d")

    Reference: 

    https://securelist.com/valleyrat-backdoor-adware/121175/           


    Tags

    MalwareThreat ActorBackdoorValleyRATRATDLLSideLoadingKeyloggerCredential HarvestingScreen captureChinaIndiaAdware

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags