Silver Fox Exploits DLL Sideloading to Deploy ValleyRAT Backdoor in China and India
August 31, 2026
Threat actors use DLL sideloading to run malicious code through a trusted process by placing a rogue libcef.dll alongside a legitimate program, such as QnWallpaper.exe loading a malicious library from its own directory to evade detection.
The campaign deploys this DLL sideloading technique to achieve persistence and concealment, allowing attacker code to execute within trusted processes and avoid user scrutiny.
ValleyRAT is a surveillance and remote-control backdoor capable of keystroke and clipboard capture, window monitoring, system information gathering, and remote command-and-control communication.
Once active, ValleyRAT can receive and execute commands, load additional malicious modules, take screenshots, and exfiltrate data, with activity tied to targets in China and India.
Experts urge users to verify software provenance, avoid questionable downloads, and not disable security products from scans to reduce infection risk.
Technical indicators include MD5 hashes for the installer and DLL, specific C2 servers and ports, and decoy domains and file paths, such as qnwallpaper.keansoft.cn and meeting.tencent.com in the C:\ directory.
The backdoor can mark its process as critical, monitor for security tools, recover after errors, and complicate incident response.
Defenders note that attackers disable Microsoft Defender via registry settings and stage components under Program Files to gain persistence and broader access.
Silver Fox is identified as the threat actor distributing ValleyRAT by disguising it as signed Chinese adware, exploiting trusted processes to bypass antivirus exclusions.
Defensive recommendations include reviewing autorun entries, identifying suspicious QN Wallpaper installations and libcef.dll, isolating affected endpoints, preserving evidence, resetting credentials, and hunting for related activity across networks.
The campaign illustrates a broader pattern of abusing legitimate software and trusted execution paths to deploy backdoors, emphasizing prevention of malicious execution pathways rather than solely blocking known ValleyRAT files.
A July 2026 report describes expansion of techniques, including more DLL-sideloading hosts, new kernel drivers, and a dual-layer recovery architecture to keep ValleyRAT running even if components are terminated.
Summary based on 3 sources
Get a daily email with more Tech stories
Sources

The Hacker News • Aug 31, 2026
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Security Affairs • Aug 31, 2026
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool