All incidents

ValleyRAT backdoor campaign uses signed adware to evade detection

malwareopenAug 31, 2026 — Aug 31, 2026
ValleyRAT backdoor campaign uses signed adware to evade detection

RESEARCHERS have uncovered a ValleyRAT backdoor campaign that distributes the malware inside digitally signed adware packages, allowing attackers to slip past many endpoint defences by exploiting user‑added antivirus exclusions. The operation, first observed on 31 August 2026, has already generated more than 100 000 detections across over 1 500 unique machines, primarily in China and India.

The malicious installers mimic legitimate software and carry a valid code‑signing certificate, which helps them bypass reputation checks. Once executed, the adware employs DLL sideloading to load ValleyRAT, a modular backdoor capable of logging keystrokes, harvesting clipboard contents, executing arbitrary commands and maintaining persistence through registry modifications.

Kaspersky’s analysis, detailed in their Securelist report, notes that the campaign does not rely on any known vulnerability and therefore carries no associated CVE identifiers. Instead, the threat leverages social engineering to convince users to add the signed installer to their antivirus exclusion list, effectively disabling real‑time scanning for that file.

Attribution points to the threat cluster tracked as Void Arachne, also referred to in some research as the Silver Fox group. The actors have focused their efforts on users in Asia, using lures that resemble popular productivity tools and media players to increase the likelihood of execution.

The campaign remains active, with recent samples showing continued evolution of the adware payload and refinements to the sideloading technique. Because no patch exists for the abuse of code signing or exclusion mechanisms, defenders must rely on behavioural controls and user awareness to reduce the risk of infection.

Organisations should enforce strict application allowlisting policies so that only trusted binaries can run, monitor for unexpected changes to antivirus exclusion lists and registry keys associated with persistence, and educate employees about the dangers of installing software from unverified sources, even when it appears to be signed. Regular audits of installed adware and the use of endpoint detection and response tools that flag anomalous DLL loading can help uncover ValleyRAT before it establishes a foothold.

Intelligence briefing updated Aug 31, 2026

Void Arachne
Root sourcesecurelist.com
Timeline Coverage

Swipe to explore timeline