A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules.
Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
In July 2026, Cato CTRL documented a Silver Fox campaign targeting a Japanese industrial manufacturer. The campaign used two previously undocumented DLL-sideloading hosts, two kernel drivers not previously linked to Silver Fox, and a dual-layer ValleyRAT recovery architecture.
During 2026, researchers observed more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, primarily in China and India. The ValleyRAT use and victim geography indicated Silver Fox was the likely operator.
A campaign distributed ValleyRAT through malicious installers posing as the QN Wallpaper application. The installer deployed modified QN Wallpaper components, disabled Windows Defender, established persistence, and sideloaded a trojanized libcef.dll through signed QnWallpaper.exe and QnwPlayer.exe.
Technical analysis of the QN Wallpaper masquerading campaign identified ValleyRAT’s AES-encrypted payload loading, persistence and anti-analysis features, data-theft functions, and svchost process-hollowing capability. Researchers also identified C2 endpoints at 103.45.66.18 on ports 441, 442, and 443, and 192.253.225.173 on ports 6666 and 8888.
ToddyCat used vlc.exe to load a payload named libvlc.dll into its address space and launch a remote-access trojan.
An unnamed Asia-based APT group used OLEVIEW.exe to load a malicious iviewers.dll library and execute a backdoor.
GhostEmperor placed a malicious msedgeupdate.dll in the directory of the legitimate Edge update component meupdate.exe for DLL sideloading.
Babuk abused the NTSD.exe debugger for DLL sideloading to deliver ransomware to target devices.
REvil abused the Windows Defender system file MsMpEng.exe to load a malicious DLL containing ransomware.
APT10 used DLL sideloading to deliver the LODEINFO backdoor to targeted devices for cyber-espionage.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
12 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcescworld.com
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceencyclopedia.kaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.