The ValleyRAT backdoor is being distributed through a modified version of the QN Wallpaper adware, leveraging DLL sideloading via a malicious libcef.dll. This campaign, attributed to the Silver Fox threat actor, uses signed installers that masquerade as legitimate tools like Google Chrome or DingTalk to bypass security measures and user suspicion. By exploiting the common practice of users adding adware to exclusion lists, the attackers successfully deploy complex infection chains.
Once active, ValleyRAT provides extensive spyware capabilities, including keylogging, clipboard monitoring, and remote command execution. It employs sophisticated persistence and self-protection techniques, such as marking its process as critical to trigger a Blue Screen of Death (BSOD) if terminated and injecting code into svchost to monitor and restart its own process. The malware's modular nature allows it to download additional payloads, making it a highly flexible tool for both cyberespionage and financial gain.
Top comments (0)