478/69 Wednesday, September 2, 2026

Researchers from Kaspersky have discovered a new cyberattack campaign in which the dangerous ValleyRAT malware is bundled with adware to evade detection. Initial findings indicate that the Silver Fox threat group is behind the campaign, with the objective of stealing sensitive information and gaining control of victims’ systems. The attack has affected more than 1,500 users, particularly in China and India, with more than 100,000 detections reported in 2026. This reflects the increasingly deceptive methods used by attackers, who abuse seemingly harmless programs to lower victims’ suspicion during software installation.
In this attack, the hackers modified a Chinese wallpaper management program called QN Wallpaper and were also able to disguise installer filenames as applications such as Google Chrome or DingTalk. When users install the program, the attackers use a technique known as DLL sideloading by loading a malicious libcef.dll file that runs in the background under the process of a trusted program. At the same time, the malware modifies the DisableAntiSpyware registry key to disable Windows Defender. Once ValleyRAT successfully enters the system, it connects to a command-and-control server to monitor keystrokes, copy clipboard data, and collect information about the system environment. The malware can also inject code into the svchost.exe process to maintain persistence. If an attempt is made to forcibly terminate this process, the malware is designed to respond by immediately crashing the operating system.
To respond to and reduce the risk of this type of attack, administrators and general users should exercise strict caution when downloading and installing third-party software, even if the program appears trustworthy or contains properly signed components. Administrators should closely monitor system behavior for abnormal DLL loading activity and should never add untrusted software to antivirus exclusion lists. Organizations should also establish clear software usage policies to prevent ordinary applications from becoming hidden channels for malware to access and damage network systems.
