ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading

ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper (TL-2026-2256), also tracked as Winos 4.0, is a high-severity malware campaign, first published 2026-08-31. It is attributed to Void Arachne (China) with medium confidence, affects Microsoft Windows, maps to 17 MITRE ATT&CK techniques (T1055, T1056, T1057), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2256

Threat ID
TL-2026-2256
Also known as
Winos 4.0, Winos, Trojanized QN Wallpaper
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-31
Last reviewed
2026-08-31
Attribution
Void Arachne
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
consumer, government administration, finance, health, manufacturing
Target regions
china, india, russia, japan, malaysia, taiwan
Detection rules
9
Indicators of compromise
17

Malware and tooling in ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper

Malware and tooling: Mariposa, ValleyRAT, Winos, Winos 4.0, BootRepair.sys / EnPortv.sys, WatchDog Antimalware driver (amsdk.sys)

Silver Fox is distributing the ValleyRAT (Winos 4.0) backdoor disguised as the QN Wallpaper adware tool. A signed QnWallpaper.exe installer sideloads a malicious libcef.dll, disables Windows Defender via registry modification, and installs a backdoor capable of keylogging, clipboard theft, screenshot capture, and loading additional malicious modules. Kaspersky recorded over 100,000 detections affecting more than 1,500 unique users, mostly in China and India, in 2026.

How ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper works

Kaspersky telemetry has identified a wave of ValleyRAT (also tracked as Winos 4.0) distribution disguised as the legitimate Chinese desktop-customization adware application QN Wallpaper. Attackers repackaged the adware installer so that its signed executable, QnWallpaper.exe, is placed alongside a malicious libcef.dll in the same install directory (C:\Program Files\QNWallpaper\5.4.0.1662\); when the signed process starts it resolves and loads the attacker's DLL from that directory instead of (or in addition to) any legitimate Chromium Embedded Framework component, executing the backdoor's loader stage under the umbrella of a validly signed binary. The loader disables Windows Defender by setting the DisableAntiSpyware registry value, adds itself to system autorun so it survives reboot, and attempts privilege escalation via the `runas` verb when the current user is not an administrator. The delivery site (qnwallpaper[.]keansoft[.]cn) fronts the trojanized adware download, while a Tencent Meeting URL (meeting[.]tencent[.]com) is used as a decoy landing page during the infection flow.

Once installed, ValleyRAT/Winos 4.0 behaves as a full-featured, plugin-based backdoor: it harvests keystrokes and clipboard contents, captures screenshots, can reboot or shut down the host, and downloads/loads additional malicious modules on operator command. To resist takedown it flags its own process as critical to the OS, so any attempt to forcibly terminate it triggers a Windows blue-screen-of-death rather than allowing the process to be killed cleanly. Kaspersky recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users during 2026, concentrated in China and India, consistent with an opportunistic, adware-bundled distribution model rather than narrowly targeted spear-phishing.

ValleyRAT/Winos 4.0 is the signature backdoor of the Chinese-speaking cybercrime/espionage cluster tracked as Silver Fox (aka SwimSnake, The Great Thief of Valley, UTG-Q-1000, Void Arachne), an evolution of legacy Gh0st RAT-derived tooling built around a modular plugin architecture. A leaked builder (compiled March 2025) exposed the backdoor's internals: 19 paired 32/64-bit main plugins covering beaconing, keylogging, audio/video/screen capture, remote terminal, file/registry management, scheduled-task persistence, proxy tunneling, a DDoS stress-test module, and credential theft from Chinese applications (QQ, WeChat, Telegram) and browsers. A separate Driver Plugin embeds a 64-bit kernel-mode rootkit derived from the public 'Hidden' rootkit project that hides registry keys/files, protects the malware's process, injects shellcode via APC queuing, and force-deletes 50+ competing EDR/AV drivers (including Kaspersky, Qihoo 360, Huorong, and Tencent security products) at startup. Related Silver Fox campaigns documented in the same period show the group's rapid tooling evolution: abuse of a Microsoft-signed WatchDog Antimalware driver (amsdk.sys) to kill PP/PPL-protected security processes (BYOVD), a three-driver BYOVD chain (adding BootRepair.sys and EnPortv.sys) against a Japanese industrial manufacturer via trusted-software hijacking (ConvertToPDF.exe/PDFDirect.exe sideloading), and tax-themed phishing lures against Indian and Russian organizations that deliver a new ValleyRAT plugin loading a previously undocumented Python-based backdoor, ABCDoor. This QN Wallpaper campaign reuses the DLL-sideload technique previously seen in a 2025 PNGPlug loader campaign that also abused libcef.dll, suggesting shared tooling/infrastructure across the actor's distribution chains.

MITRE ATT&CK techniques used in TL-2026-2256

Defense Evasion

T1055 Process Injection; T1574 Hijack Execution Flow

Collection

T1056 Input Capture; T1113 Screen Capture; T1123 Audio Capture

Discovery

T1057 Process Discovery; T1082 System Information Discovery

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Execution

T1129 Shared Modules

Initial Access

T1195 Supply Chain Compromise

execution

T1204 User Execution

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Credential Access

T1555 Credentials from Password Stores

Command and Control

T1571 Non-Standard Port; T1573 Encrypted Channel

Affected products and versions in ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper

  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11
  • Keansoft — QN Wallpaper
    Vulnerable versions: 5.4.0.1662 (trojanized redistribution)

Remediation for ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper

Immediate actions

  • Block the confirmed C2 IPs 103.45.66.18 (TCP 441/442/443) and 192.253.225.173 (TCP 6666/8888) and the delivery domain qnwallpaper[.]keansoft[.]cn at perimeter/proxy/DNS
  • Hunt for QnWallpaper.exe co-located with libcef.dll outside a legitimate Chromium Embedded Framework install, and for the install path C:\Program Files\QNWallpaper\5.4.0.1662\
  • Audit endpoints for an unauthorized DisableAntiSpyware registry value under the Windows Defender policy keys and revert it
  • Isolate and re-image any host where the malicious process could not be terminated (critical-process flag triggering BSOD is a strong compromise indicator)

Workarounds

  • Block or alert on any non-Chromium-Embedded-Framework process loading a file named libcef.dll
  • Monitor for processes that set themselves as critical (bugcheck-on-termination) as a high-confidence indicator of anti-kill malware

Longer-term hardening

  • Deploy application allowlisting / code-integrity policy to block unauthorized DLLs loading into signed third-party executables (DLL sideloading defense)
  • Enable Microsoft Defender tamper protection and attack-surface-reduction rules that block unauthorized changes to security-product registry settings
  • Deploy and keep current the Microsoft vulnerable-driver blocklist to close the BYOVD path (amsdk.sys, BootRepair.sys, EnPortv.sys) this actor uses in related campaigns to disable EDR/AV
  • Restrict installation of adware/PUA-bundled software via endpoint/download policy given this actor's pattern of trojanizing legitimate consumer utilities

Timeline of ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper

  • The ValleyRAT/Winos 4.0 32-bit PE builder used across the malware family is compiled; ~85% of ~6,000 later-observed samples emerge within six months of this build, per Check Point Research.
  • Silver Fox is observed exploiting a Microsoft-signed WatchDog Antimalware driver (amsdk.sys) to terminate PP/PPL-protected security processes before deploying ValleyRAT.
  • Kaspersky detects a wave of tax-authority-themed phishing emails targeting Indian users that deliver ValleyRAT, attributed to Silver Fox.
  • A similar tax-themed campaign begins targeting Russian organizations; the delivered ValleyRAT plugin loads a previously undocumented Python-based backdoor codenamed ABCDoor.
  • The ABCDoor/tax-themed India-Russia campaign is publicly reported.
  • Cato Networks documents Silver Fox targeting a Japanese industrial manufacturer with an updated attack chain: two new DLL-sideloading hosts (ConvertToPDF.exe, PDFDirect.exe) and two new kernel drivers (BootRepair.sys, EnPortv.sys) used to disable security tooling before deploying ValleyRAT.
  • Kaspersky/The Hacker News report the QN Wallpaper-disguised ValleyRAT campaign: a signed QnWallpaper.exe sideloads a malicious libcef.dll, disables Windows Defender, and installs the ValleyRAT backdoor; 100,000+ detections and 1,500+ unique victims recorded in 2026, mostly in China and India.

Sources cited for ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper

More in malware

Detection coverage for TL-2026-2256

As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2256 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats