1. Executive summary
Kaspersky reports a campaign distributing the ValleyRAT backdoor disguised as a signed Chinese desktop-wallpaper adware application (QN Wallpaper), delivered via installers masquerading as legitimate software (DingTalk, Google Chrome, a Tencent Meetings download page). The malicious installer disables Windows Defender via the DisableAntiSpyware registry key, deploys a DLL-sideloading chain through a trojanised libcef.dll, and delivers an AES-encrypted ValleyRAT payload with keystroke logging, clipboard capture, screenshot capability, process-protection tricks and a modular loader. Kaspersky attributes the campaign to the Silver Fox group — this attribution is unconfirmed: no MITRE ATT&CK profile for Silver Fox exists in our verified reference data, and the attribution rests on a single vendor report. No CVE is involved; this is a social-engineering-and-sideloading threat, not a patchable vulnerability. EMEA financial services exposure appears limited — observed victims are concentrated in China and India — but the delivery pattern (signed adware that users may add to AV exclusions) is directly relevant to endpoint policy and third-party software controls.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 24: digital operational resilience testing — general requirements | The infection chain succeeds specifically because a signed, user-installed adware binary runs outside normal application allow-listing and is commonly added to security-tool exclusions by users themselves. | Clients should test (e.g. in purple-team or scenario exercises) whether user-installed PUP/adware and user-created AV exclusions can carry a sideloaded payload past current endpoint controls; this is a distinct test case, not a generic patch test. |
| DORA Art. 28: ICT third-party risk — general principles | The malicious chain abuses a genuine third-party vendor product (QN Wallpaper by Keansoft) as its signed host process, and the initial installers impersonate other third-party products (DingTalk, Chrome, Tencent). | Third-party software intake policy should treat unsigned-download-channel installers of vendor products as untrusted regardless of the vendor name in the filename; verify distribution channel, not product identity. |
No NIS2 or UK NIS article is engaged by a fact distinctive to this item.
3. Technical analysis & attack chain
Attribution caveat: Kaspersky assesses Silver Fox as the likely operator, based on the ValleyRAT family association and the China/India victim geography. This is single-sourced and there is no MITRE ATT&CK profile for Silver Fox in our verified reference data — treat the attribution as unconfirmed. The IOC set is likewise single-sourced (one vendor report); verify before enforcement.
Confirmed attack chain, per the source:
- Delivery. The victim obtains an installer named
FS_SETUP_<two-letter suffix>_<number>.exe. The suffix determines the decoy behaviour:DDinstalls DingTalk,GGinstalls Google Chrome,HYopenshxxps://meeting[.]tencent[.]com/download/. These actions are attention-diversion; the malicious behaviour is identical regardless of suffix. Distribution is via ad/affiliate networks, exploiting the fact that the underlying adware is developer-signed and users frequently add such apps to security-tool exclusions. - Deployment. The installer unpacks a modified QN Wallpaper (genuine Chinese adware,
hxxps://qnwallpaper[.]keansoft[.]cn/) plus malicious components toC:\Program Files\QNWallpaper\5.4.0.1662\<random alphanumeric string>\, and adds it to registry autorun entries. - Defender disable. The installer sets the
DisableAntiSpywareregistry key to turn off Windows Defender, then launchesQnWallpaper.exe. - DLL sideloading.
QnWallpaper.exedepends onlibcef.dll; the trojanisedlibcef.dll(MD507ddbbe2c71c45577a7a4fbcdba0df91) is loaded at process start.QnWallpaper.exealso launchesQnwPlayer.exe, which loads the same malicious DLL. The adware's genuine functions are stubbed into an infinite sleep; a fallback function loads the original library's functions from disk if the sleep is ever interrupted. Malicious execution triggers fromDllMainon load; the library also exports aRunDLLfunction that initiates the same code — never called by QnWallpaper, and Kaspersky suspects it was intended for manual invocation viarundll32or a not-shipped executable. - Persistence. On load, the DLL adds a file-extension association and drops a file with that extension into
C:\Documents and Settings\<username>\Start Menu\Programs\Startup\soQnWallpaper.exepersists at startup. - Privilege check. A wrapper-function chain reaches the main malicious routine (
mw_entry), which checks whether the current user is in the Administrators group; if not, it attempts elevation via therunasutility. - Payload selection and decryption. With admin privileges, the code identifies which process the DLL was loaded into and selects one of two AES-encrypted DLL payloads accordingly — both contain ValleyRAT and differ only in configuration (C2 addresses). After decryption,
libcef.dllvalidates PE-header magic signatures; on failure it releases resources and does nothing. On success it maps the payload into the process's memory and transfers control viaDllMain. - Backdoor operation. ValleyRAT parses a key:value configuration stored as a single reversed string (character order restored at parse time). Known keys:
p?(C2 IP),o?(C2 port),t?(protocol: 1 = TCP, 0 = UDP),dd(pre-execution sleep),cl(post-command sleep),bz(config creation date),bh(mark process as critical so termination triggers a BSOD: 1/0),ll(check for security/traffic-analysis tools: 1/0),sh(inject a restart-watchdog into svchost: 1/0). - Spyware and anti-analysis. The backdoor logs keystrokes and tracks the focused window via DirectInput8 functions, and captures clipboard contents; all collected data is written to a file on disk. If
ll= 1, it periodically enumerates windows (viaEnumWindows) looking for process-/traffic-analysis applications. Theshwatchdog injected into svchost restarts the backdoor if its execution is interrupted; thebhoption marks the process critical so killing it causes a BSOD. - Modular capability. On operator command with a link, the backdoor downloads and executes a file from the C2 or a third-party address. Shellcode modules are launched via process hollowing into svchost; DLL modules are loaded into the backdoor's own process,
DllMaincalled, an exportedMainfunction invoked, then the library unloaded. The source lists screenshots and system-information collection among its on-command capabilities.
Scale: Kaspersky detected ValleyRAT and associated malware more than 100,000 times across 2026, affecting 1,500+ unique users, primarily in China and India. Single-sourced figures.
4. Mitigation & containment
P1 — within 24 hours
- Hunt for the installer filename pattern
FS_SETUP_*_*.exeand the directoryC:\Program Files\QNWallpaper\across the estate; any hit is a presumptive compromise requiring full host triage. - Block the four C2 endpoints at egress:
103.45.66[.]18(ports 441/442/443) and192.253.225[.]173(ports 6666/8888). - Verify Windows Defender is enabled on all endpoints; check for and remove the
DisableAntiSpywareregistry value (under the Defender policy keys) and alert on any write to it. - Sweep AV/EDR exclusion lists for user-added exclusions referencing QNWallpaper, QnWallpaper.exe, QnwPlayer.exe or
C:\Program Files\QNWallpaper\— the source notes users commonly exclude adware, which is precisely what this chain exploits.
P2 — within 72 hours
- Alert on the persistence mechanism: any file dropped into
...\Start Menu\Programs\Startup\with a newly registered file-extension association, and autorun entries pointing atQnWallpaper.exe. - Monitor for
runasinvocation originating fromQnWallpaper.exe/QnwPlayer.exe/libcef.dllcontext — legitimate wallpaper adware has no reason to elevate. - Review proxy/DNS logs for requests to
qnwallpaper[.]keansoft[.]cnand for downloads ofFS_SETUP_*binaries; the installers impersonate DingTalk, Chrome and Tencent Meetings downloads — confirm software-distribution policy blocks user-sourced installers of these products. - If a compromise is confirmed: isolate the host, capture memory (the payload is reflective/in-memory after decryption), remove the Startup-folder artefact, the extension association and the autorun entry, and rotate any credentials used on the host given keystroke and clipboard capture.
P3 — within 7 days
- Enforce application allow-listing or at minimum block user installation of PUP/adware-class software on corporate endpoints; the source's core recommendation is policy on third-party software on work devices and user awareness.
- Add the file hashes in §5 to blocklists; treat any
libcef.dlloutside a verified Chromium/Electron application directory as suspicious and verify its signature. - Include "signed adware used as sideload host" as a test case in resilience testing (see DORA Art. 24 row above).
5. Indicators of compromise
| Type | Value | Confidence | Source |
|---|---|---|---|
| md5 | c24e99f9437feacaa63766a3cde3fe3d | High | Kaspersky (malicious installer / <random>Nedca.exe copy) |
| md5 | 7ad1e3ef4e6d9d636c9e7e967733850e | High | Kaspersky (1.zip archive) |
| md5 | 96b4c1d0683dce22bd3223e1e40689c1 | High | Kaspersky (7z.dll) |
| md5 | 9b86d3ab6cef15c633933fbbeab39c0a | High | Kaspersky (7z.exe) |
| md5 | edfdc30cbd85879776b8f735ea7de1f1 | High | Kaspersky (chrome_elf.dll) |
| md5 | 07ddbbe2c71c45577a7a4fbcdba0df91 | High | Kaspersky (malicious libcef.dll) |
| md5 | 48826d5ca845979d2e6ebd66dc1aae90 | High | Kaspersky (PeLoader — encrypted backdoor container) |
| md5 | 6c158c0f8e029342192d4f0d72e102b7 | High | Kaspersky (QnWallpaper.exe) |
| md5 | 9a71d6a41cd258b9e89cdc5fc224de73 | High | Kaspersky (QnwPlayer.exe) |
| md5 | 8a626d844943da3456b044f38deae3a2 | Medium | Kaspersky (listed without description in source IOC block) |
| ipv4 | 103.45.66[.]18 | High | Kaspersky (C2, ports 441/442/443) |
| ipv4 | 192.253.225[.]173 | High | Kaspersky (C2, ports 6666/8888) |
| domain | qnwallpaper[.]keansoft[.]cn | Medium | Kaspersky (vendor site of the abused adware — legitimate domain, use for download-channel monitoring, not blanket blocking) |
| filename | FS_SETUP_DD_173.exe | High | Kaspersky (observed installer name) |
| filename | FS_SETUP_GG_173.exe | High | Kaspersky (observed installer name) |
| filename | FS_SETUP_HY_173.exe | High | Kaspersky (observed installer name) |
md5 c24e99f9437feacaa63766a3cde3fe3d
md5 7ad1e3ef4e6d9d636c9e7e967733850e
md5 96b4c1d0683dce22bd3223e1e40689c1
md5 9b86d3ab6cef15c633933fbbeab39c0a
md5 edfdc30cbd85879776b8f735ea7de1f1
md5 07ddbbe2c71c45577a7a4fbcdba0df91
md5 48826d5ca845979d2e6ebd66dc1aae90
md5 6c158c0f8e029342192d4f0d72e102b7
md5 9a71d6a41cd258b9e89cdc5fc224de73
md5 8a626d844943da3456b044f38deae3a2
ipv4 103.45.66[.]18
ipv4 192.253.225[.]173
domain qnwallpaper[.]keansoft[.]cn
filename FS_SETUP_DD_173.exe
filename FS_SETUP_GG_173.exe
filename FS_SETUP_HY_173.exe
All indicators are single-sourced (one vendor report); verify before enforcement.
6. Detection
rule ValleyRAT_QNWallpaper_Sideload_libcef
{
meta:
author = "Adverse Trace"
date = "2026-08-31"
reference = "https://securelist.com/valleyrat-backdoor-adware/121175/"
description = "Detects trojanised libcef.dll sideloaded by QN Wallpaper delivering ValleyRAT, and the malicious installer copy"
strings:
$installer = "FS_SETUP_" wide ascii
$nedca = "Nedca.exe" wide ascii
$qnpath = "QNWallpaper\\5.4.0.1662" wide ascii
$startup = "Start Menu\\Programs\\Startup" wide ascii
$rundll_export = "RunDLL" ascii
$defender = "DisableAntiSpyware" wide ascii
condition:
uint16(0) == 0x5A4D and 4 of them
}
Note: RunDLL and DisableAntiSpyware are individually low-specificity strings; the rule relies on their combination with the QN Wallpaper path and installer artefacts. The PeLoader filename and the mw_entry label are internal analysis names from the report, not strings confirmed present in the binaries, and are deliberately excluded.
title: ValleyRAT via QN Wallpaper - Defender disable, startup drop and runas elevation
id: 8f3c1d52-9a47-4b6e-8c2f-1d5e6a7b9c03
status: experimental
description: Detects the ValleyRAT/QN Wallpaper chain - DisableAntiSpyware registry write, QnWallpaper autorun/startup persistence, and runas elevation from the adware context.
references:
- https://securelist.com/valleyrat-backdoor-adware/121175/
author: Adverse Trace
date: 2026-08-31
logsource:
product: windows
category: registry_set
detection:
selection_defender:
TargetObject|contains: 'DisableAntiSpyware'
condition: selection_defender
falsepositives:
- Legitimate enterprise endpoint-hardening tools setting Defender policy keys
level: high
---
title: ValleyRAT via QN Wallpaper - persistence via Startup folder and autorun
id: 2b7e4a91-6c3d-4f8a-9e1b-7a2c5d8f0e14
status: experimental
description: QnWallpaper.exe added to autorun or Startup folder by the sideloaded libcef.dll.
references:
- https://securelist.com/valleyrat-backdoor-adware/121175/
author: Adverse Trace
date: 2026-08-31
logsource:
product: windows
category: process_creation
detection:
selection_image:
Image|endswith: '\QnWallpaper.exe'
selection_startup:
CommandLine|contains: 'Start Menu\Programs\Startup'
filter_legit:
ParentImage|endswith: '\explorer.exe'
condition: 1 of selection_* and not 1 of filter_legit*
falsepositives:
- Genuine QN Wallpaper installs (verify download channel and libcef.dll signature)
level: high
7. Sources
- Kaspersky Securelist, "ValleyRAT masquerading as adware", https://securelist.com/valleyrat-backdoor-adware/121175/, 2026-08-31
8. Adverse Trace position
This is a capable, multi-stage backdoor delivered through a distribution channel — signed adware and affiliate networks — that many endpoint programmes handle poorly, and the chain includes Defender disable, startup persistence, elevation via runas, in-memory payload injection, keystroke/clipboard capture and a modular loader with process-hollowing execution: on a compromised host, assume credential exposure. Severity for EMEA financial services is moderate rather than high — the malware is potent, but observed victim geography (China and India) and the consumer-adware delivery vector suggest limited current targeting of our clients' region, and no CVE means no patch gap to close; the exposure is policy- and behaviour-shaped. The Silver Fox attribution and the entire IOC set are single-sourced from one vendor report with no MITRE profile in our verified data — unconfirmed until corroborated. We will monitor for corroborating reporting from additional vendors, for any EMEA victimology, and for new C2 infrastructure or installer variants beyond the FS_SETUP_* pattern; clients with China- or India-based staff or partners should prioritise the P1 hunt items.
Published via PulseTrace — Adverse Trace threat intelligence.