securelist.com 8/31/2026, 10:11:38 AM · external

ValleyRAT backdoor hides in adware, uses DLL sideloading to spy

ValleyRAT backdoor hides in adware, uses DLL sideloading to spy
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses the ValleyRAT backdoor, which is disguised as adware and distributed through a malicious installer. It highlights how attackers exploit adware to deliver sophisticated malware under the guise of legitimate applications. Key points include:

1. **Malicious Installer:** The installer behaves differently based on its file name suffix, distracting users from its true function.

2. **DLL Sideloading:** The backdoor uses a technique called DLL sideloading via the 'libcef.dll' library, allowing malicious code to execute while appearing benign.

3. **Operational Tactics:** ValleyRAT collects sensitive data like keystrokes and clipboard contents, can take screenshots, and offers various malicious functionalities like downloading additional modules or restarting the system.

4. **Targets and Attribution:** Over 100,000 detections of the backdoor occurred in 2026, primarily affecting users in China and India, linked to the group known as Silver Fox.

5. **Conclusion:** The case exemplifies the dangers posed by adware that can conceal more harmful intentions, with recommendations for organizations and individuals on cybersecurity practices.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline