Silver Fox Exploits DLL Sideloading to Deploy ValleyRAT Backdoor in China and India

August 31, 2026
Silver Fox Exploits DLL Sideloading to Deploy ValleyRAT Backdoor in China and India
  • Threat actors use DLL sideloading to run malicious code through a trusted process by placing a rogue libcef.dll alongside a legitimate program, such as QnWallpaper.exe loading a malicious library from its own directory to evade detection.

  • The campaign deploys this DLL sideloading technique to achieve persistence and concealment, allowing attacker code to execute within trusted processes and avoid user scrutiny.

  • ValleyRAT is a surveillance and remote-control backdoor capable of keystroke and clipboard capture, window monitoring, system information gathering, and remote command-and-control communication.

  • Once active, ValleyRAT can receive and execute commands, load additional malicious modules, take screenshots, and exfiltrate data, with activity tied to targets in China and India.

  • Experts urge users to verify software provenance, avoid questionable downloads, and not disable security products from scans to reduce infection risk.

  • Technical indicators include MD5 hashes for the installer and DLL, specific C2 servers and ports, and decoy domains and file paths, such as qnwallpaper.keansoft.cn and meeting.tencent.com in the C:\ directory.

  • The backdoor can mark its process as critical, monitor for security tools, recover after errors, and complicate incident response.

  • Defenders note that attackers disable Microsoft Defender via registry settings and stage components under Program Files to gain persistence and broader access.

  • Silver Fox is identified as the threat actor distributing ValleyRAT by disguising it as signed Chinese adware, exploiting trusted processes to bypass antivirus exclusions.

  • Defensive recommendations include reviewing autorun entries, identifying suspicious QN Wallpaper installations and libcef.dll, isolating affected endpoints, preserving evidence, resetting credentials, and hunting for related activity across networks.

  • The campaign illustrates a broader pattern of abusing legitimate software and trusted execution paths to deploy backdoors, emphasizing prevention of malicious execution pathways rather than solely blocking known ValleyRAT files.

  • A July 2026 report describes expansion of techniques, including more DLL-sideloading hosts, new kernel drivers, and a dual-layer recovery architecture to keep ValleyRAT running even if components are terminated.

Summary based on 3 sources


Get a daily email with more Tech stories

More Stories