Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: valleyrat (2 articles)Clear

ValleyRAT backdoor hides in signed adware users add to antivirus exclusions

Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.

Check
Warn users not to install questionable or adware-bundled software and never to add it to antivirus exclusion lists, and hunt for signed processes side-loading unexpected libraries or disabling Defender.
Affected
Windows users who install low-reputation adware and exclude it from antivirus scanning; the signed host process side-loads ValleyRAT, which disables Defender and gives attackers full remote control of the machine.
Fix
Block low-reputation and adware software through application control, avoid broad antivirus exclusions, monitor for DLL sideloading from signed processes and Defender being disabled, and treat trusted-but-questionable software as a real threat vector.

China-linked group is sending 1,600 fake tax-audit emails to Indian and Russian companies, then dropping a brand-new backdoor called ABCDoor

Kaspersky tracked a China-based group called Silver Fox running a tax-themed phishing campaign against organizations in India, Russia, Indonesia, Japan, and South Africa. Phishing emails impersonate the Indian Income Tax Department or Russian tax service with subjects about audits or 'lists of tax violations.' Inside the attached archive sits a modified Rust loader that pulls down a known backdoor called ValleyRAT, plus a brand-new Python-based backdoor called ABCDoor. ABCDoor handles screen recording, keystroke control, clipboard theft, and file operations. Kaspersky logged 1,600+ phishing emails between January and February 2026 across industrial, consulting, retail, and transportation sectors.

Check
Search proxy and DNS logs for connections to abc.haijing88.com since December 2025. Hunt endpoints for pythonw.exe processes initiating outbound HTTPS to unfamiliar destinations.
Affected
Organizations in India, Russia, Indonesia, Japan, and South Africa, particularly in industrial, consulting, retail, and transportation sectors. Finance and accounting staff who routinely receive tax correspondence are the highest-risk role. Multinationals with operations in any of these regions face the same risk through local subsidiaries.
Fix
Block abc.haijing88.com and related Silver Fox infrastructure at the DNS resolver. Train finance staff that real tax correspondence never arrives as a ZIP or RAR archive of 'violations' to download. Quarantine any host running pythonw.exe with unexpected outbound HTTPS, and remove FFmpeg installations not authorized by IT. Rotate credentials on suspected compromised hosts and reimage.