Recent findings from Kaspersky reveal that the threat actor known as Silver Fox is actively distributing the ValleyRAT backdoor by disguising it within a signed Chinese adware application, specifically QN Wallpaper. This malware operates under a trusted process, allowing it to evade detection by antivirus software, particularly when users intentionally include such applications in their antivirus exclusions. This tactic underscores the evolving sophistication of cyber threats that exploit user trust in seemingly benign software.
For businesses, the implications are profound. The use of trusted applications as vectors for malware highlights the need for a comprehensive approach to cybersecurity that goes beyond traditional antivirus solutions. Organizations must educate their employees about the risks of whitelisting applications without thorough scrutiny and implement more robust endpoint detection and response (EDR) strategies. This incident serves as a stark reminder of the importance of maintaining vigilance against emerging threats in the cybersecurity landscape, particularly as attackers increasingly leverage trusted processes to deploy malicious payloads.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html)*