ValleyRAT backdoor hides in signed adware users add to antivirus exclusions
Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.
- Check
- Warn users not to install questionable or adware-bundled software and never to add it to antivirus exclusion lists, and hunt for signed processes side-loading unexpected libraries or disabling Defender.
- Affected
- Windows users who install low-reputation adware and exclude it from antivirus scanning; the signed host process side-loads ValleyRAT, which disables Defender and gives attackers full remote control of the machine.
- Fix
- Block low-reputation and adware software through application control, avoid broad antivirus exclusions, monitor for DLL sideloading from signed processes and Defender being disabled, and treat trusted-but-questionable software as a real threat vector.