securityaffairs.com 8/31/2026, 8:32:16 PM · external

ValleyRAT malware hides in fake wallpaper app to spy on users

ValleyRAT malware hides in fake wallpaper app to spy on users
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor

THE article discusses ValleyRAT, a sophisticated malware that disguises itself as legitimate adware to infiltrate systems. Researchers from Kaspersky identified a modified version of the QN Wallpaper application which serves as a delivery mechanism for the ValleyRAT backdoor. The malware uses DLL sideloading to execute malicious code under the guise of a trusted application, evading detection. Once installed, it can steal sensitive data, monitor user activity, and execute commands.

ValleyRAT has been linked to the Silver Fox actor group, primarily affecting users in China and India. The findings underscore the risks associated with seemingly legitimate software and the need for vigilance against such threats.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline