ValleyRAT, also known as Winos 4.0, is a modular Windows backdoor with remote-control, surveillance, reconnaissance, and payload-delivery capabilities. It collects host details, active-window information, keystrokes, clipboard contents, and screenshots, and can exfiltrate collected keylogging and clipboard data. Operators can issue commands to reboot or shut down the host, clear logs, update command-and-control configuration, and retrieve additional DLL or shellcode modules. Downloaded shellcode may be executed through process hollowing, and the malware can inject into a Windows process to recover execution after termination.
ValleyRAT uses defense-evasion and resilience features including encrypted in-memory payload loading, security- and traffic-analysis tool discovery, critical-process protection that can crash the host if forcibly terminated, and configuration obfuscation. Observed delivery chains have trojanized the legitimate QN Wallpaper application, abusing DLL sideloading through signed executables to load an encrypted ValleyRAT payload in memory. Associated installers establish autorun persistence, attempt to disable Microsoft Defender, and may seek elevated privileges.
ValleyRAT has been observed in campaigns affecting users primarily in China and India, as well as phishing activity targeting organizations in Japan and Indian taxpayers. Activity involving the QN Wallpaper delivery chain has been assessed as likely linked to the China-nexus Silver Fox threat actor, although ValleyRAT attribution is not exclusive because the family has been used by multiple actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-52271 documents how an affected version of wsftprm.sys can be abused to terminate protected processes.
"It's worth noting that the NSecKrnl driver is susceptible to a known security flaw (CVE-2025-68947, CVSS score: 5.7) that could be exploited to terminate arbitrary processes."
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
Silver Fox has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT. A malicious QN Wallpaper installer also delivers ValleyRAT through a DLL sideloading chain.
...in addition to long-used malware such as ValleyRAT, also known as Winos 4.0.
Howler Cell identified a new 32-bit malicious installer disguised as a Google Chrome installer, which kickstarts a multi-stage delivery chain, ultimately deploying the ValleyRAT remote access trojan.
The results of the IDS-rules detection are compatible with Win32/ProcessKiller, Winos4.0 and Backdoor SilverFox which both have the alias ValleyRAT.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware can inject code into svchost, which causes the backdoor to restart after it is terminated.
To execute shellcode, the backdoor uses Process Hollowing, injecting it into an svchost process.
“[DLL sideloading is used] to load AES-encrypted payloads in memory.”
The malicious DLL extracts an encrypted ValleyRAT payload from a PeLoader file or from the DLL resources; both variants are encrypted with AES.
The archive downloaded from the site maintains the same file name while its hash changes on every download... a wrapper installer... launches the first stage payload.
The malware can inject code into svchost, which causes the backdoor to restart after it is terminated.
866 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
183 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated remote-access implant that collects system information, captures screenshots, can reboot or shut down hosts, wipes logs, updates C2 addresses, downloads additional DLL or shellcode modules, and exfiltrates keylogger and clipboard data. It protects its process and checks for analysis-related windows.
A remote-access backdoor distributed through DLL sideloading in a digitally signed QN Wallpaper executable. It inventories victim systems, logs keystrokes, captures clipboard contents and screenshots, monitors the active window, can clear logs, alter C2 addresses, shut down or reboot the host, and download additional DLL or shellcode modules. It uses process hollowing and svchost injection for execution/persistence; configured samples can mark their process critical, potentially causing a BSOD when forcibly terminated.
A remote-access backdoor that uses DLL sideloading through a modified, signed QN Wallpaper executable to execute in a trusted process and evade signature-based controls. It can disable Windows Defender, establish autorun persistence, seek elevation using runas, collect sensitive data, capture screenshots, deploy additional malicious modules, and mark its process as critical to cause a BSOD if terminated.
A remote-access backdoor delivered through DLL sideloading of a malicious libcef.dll alongside the legitimate QN Wallpaper application. It loads AES-encrypted payloads in memory and supports keylogging, clipboard-based credential harvesting, screenshot capture, system reconnaissance, defense evasion, persistence, and process hollowing for further payload execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.