In 2026, the ValleyRAT backdoor and related malware were detected by Kaspersky more than 100,000 times on devices belonging to over 1500 unique users, with the largest number of victims identified in India and China.
Kaspersky experts have uncovered a campaign involving the sophisticated ValleyRAT backdoor. The attackers exploited the adware application QN Wallpaper to execute the backdoor under a process signed by a legitimate developer certificate, making the attack more difficult to detect. ValleyRAT itself features spyware capabilities, enabling it to collect sensitive data such as keystrokes and clipboard contents, reboot or shut down the computer, take screenshots and deliver additional malicious modules to the device.
The infection chain begins when a user downloads an installer onto their device. That installer then deploys a modified desktop wallpaper management program disguised as the adware application QN Wallpaper. In its original form, the software delivers partner applications during installation and subsequently displays advertising banners to the user. In this campaign, however, the threat actor repurposed it to enable DLL sideloading - a technique in which a malicious DLL is distributed alongside the application, which is then used to load and execute it.
“ValleyRAT is a highly sophisticated backdoor that covertly performs spyware functions, putting sensitive data belonging to both individual users and organizations at risk. Normally these kinds of attacks rely on the fact that sometimes legitimate applications do not verify the libraries loaded into their address space. This allows attackers to replace a legitimate library with a malicious one bearing the same name, which the trusted application then loads without raising suspicion. As a result, the installation often goes unnoticed. Users often allow the installation of potentially unwanted software or adware on their devices, but this is one of the scenarios for malware to enter their computers, as our research proves. Therefore, we do not recommend ignoring antivirus messages about unwanted or adware,” says Vasily Kolesnikov, cybersecurity expert at Kaspersky.
Kaspersky researchers with a high degree of confidence attribute this campaign to SilverFox, a known operator of the malware family used in the described attacks. The group targets organizations across multiple countries for both cyberespionage and financial gain. Read the full report on Securelist.com
Kaspersky solutions will protect you from ValleyRAT backdoor, however we recommend that users: Do not install applications from untrusted or questionable sources and under no circumstances add them to security-tool exclusions. Never disable antivirus or security tools to install software and exercise caution when downloading any software to your devices.
Organizations are recommended to: Implement clear guidelines for the use of third-party software on work devices. Keep your employees informed about relevant threats. Kaspersky Automated Security Awareness Platform helps cultivate cyber-savvy behavior, including safe downloading practices. Augment existing security controls with human-led detection and global threat intelligence through solutions like Kaspersky Managed Detection and Response (MDR), which offers 24/7 monitoring, detection, investigation and rapid response to sophisticated cyberattacks. Monitor credentials for signs of compromise to mitigate risks, as a compromised account or system access can serve as a vector for further attacks on the organization. Kaspersky Digital Footprint Intelligence provides continuous monitoring across open and dark web sources, enabling timely response to potential threats.
Tracy