Date: 09/01/2026
Severity: High
Summary
The ValleyRAT campaign disguises a backdoor as signed adware, abusing the legitimate QN Wallpaper application and DLL sideloading via a malicious libcef.dll to load AES-encrypted payloads in memory. The backdoor performs keylogging, credential harvesting by capturing clipboard content, screenshot capture, system reconnaissance, defense evasion, persistence, and process hollowing for additional payload execution. The campaign primarily affected users in China and India and is likely linked to the Silver Fox threat actor.
Indicators of Compromise (IOC) List
IP Address | 103.45.66.18 192.253.225.173 |
Hash | 07ddbbe2c71c45577a7a4fbcdba0df91
8a626d844943da3456b044f38deae3a2
c24e99f9437feacaa63766a3cde3fe3d
9a71d6a41cd258b9e89cdc5fc224de73
c24e99f9437feacaa63766a3cde3fe3d
6c158c0f8e029342192d4f0d72e102b7
48826d5ca845979d2e6ebd66dc1aae90
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("103.45.66.18","192.253.225.173") or srcipaddress IN ("103.45.66.18","192.253.225.173") |
Detection Query 2 : | md5hash IN ("07ddbbe2c71c45577a7a4fbcdba0df91","48826d5ca845979d2e6ebd66dc1aae90","9a71d6a41cd258b9e89cdc5fc224de73","6c158c0f8e029342192d4f0d72e102b7","8a626d844943da3456b044f38deae3a2","c24e99f9437feacaa63766a3cde3fe3d")
|
Reference:
https://securelist.com/valleyrat-backdoor-adware/121175/