securelist · Crawled Sep 2, 2026

ValleyRAT masquerading as adware

5 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The ValleyRAT backdoor is being distributed under the guise of adware, specifically a modified version of the QN Wallpaper application. The malware uses DLL sideloading via a malicious libcef.dll to execute its payload, which includes stealing keystrokes, clipboard data, screenshots, and system information. It establishes persistence and communicates with C2 servers, with configurations allowing for process protection and module downloads. The campaign primarily targets users in China and India and is attributed to the threat actor group Silver Fox.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 5 extracted

Type Value Detail
MD5 07ddbbe2c71c45577a7a4fbcdba0df91 Details →
MD5 c24e99f9437feacaa63766a3cde3fe3d Details →
MD5 8a626d844943da3456b044f38deae3a2 Details →
IP 103[.]45[.]66[.]18 Details →
IP 192[.]253[.]225[.]173 Details →

MITRE ATT&CK TTPs 49 techniques

T1006 Direct Volume Access · Defense Evasion T1012 Query Registry · Discovery T1014 Rootkit · Defense Evasion T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053 Scheduled Task/Job · Execution T1053.003 Cron · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.005 Thread Local Storage · Defense Evasion T1055.015 ListPlanting · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1089 T1089 T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1112 Modify Registry · Defense Evasion T1129 Shared Modules · Execution T1132.001 Standard Encoding · Command And Control T1134.001 Token Impersonation/Theft · Defense Evasion T1136 Create Account · Persistence T1176 Browser Extensions · Persistence T1204.002 Malicious File · Execution T1484.002 Trust Modification · Defense Evasion T1543.001 Launch Agent · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1566 Phishing · Initial Access T1574.002 DLL Side-Loading · Persistence T1005 Data from Local System · Collection T1021 Remote Services · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1055.012 Process Hollowing · Defense Evasion T1070.003 Clear Command History · Defense Evasion T1071 Application Layer Protocol · Command And Control T1085 T1085 T1113 Screen Capture · Collection T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1213 Data from Information Repositories · Collection T1213.001 Confluence · Collection T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1566.001 Spearphishing Attachment · Initial Access