ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Overview
A cybersecurity group has reported that a threat actor known as Silver Fox is distributing a backdoor malware called ValleyRAT by disguising it as a legitimate signed adware application. This adware, specifically a desktop wallpaper tool named QN Wallpaper, is being added to users' antivirus exclusions, allowing the malware to operate undetected. The tactic of embedding malware within trusted applications poses a significant risk to users, as they may unknowingly grant access to their systems. Kaspersky, a Russian cybersecurity vendor, identified this method, which raises concerns about the security of software that users might consider harmless. This incident serves as a reminder for users to be cautious about what they exclude from their antivirus protections.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: QN Wallpaper, ValleyRAT backdoor
- Action Required: Users should avoid adding unknown or untrusted applications to antivirus exclusions and regularly update their security software.
- Timeline: Newly disclosed
Original Article Summary
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
Impact
QN Wallpaper, ValleyRAT backdoor
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should avoid adding unknown or untrusted applications to antivirus exclusions and regularly update their security software.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Kaspersky.