ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading — Threadlinqs Intelligence
As of 2026-08-31, ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading is a high-severity malware threat attributed to Void Arachne (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-2256 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Void Arachne · China · ESPIONAGE
Silver Fox is distributing the ValleyRAT (Winos 4.0) backdoor disguised as the QN Wallpaper adware tool. A signed QnWallpaper.exe installer sideloads a malicious libcef.dll, disables Windows Defender
Kaspersky telemetry has identified a wave of ValleyRAT (also tracked as Winos 4.0) distribution disguised as the legitimate Chinese desktop-customization adware application QN Wallpaper. Attackers repackaged the adware installer so that its signed executable, QnWallpaper.exe, is placed alongside a malicious libcef.dll in the same install directory (C:\Program Files\QNWallpaper\5.4.0.1662\); when the signed process starts it resolves and loads the attacker's DLL from that directory instead of (or in addition to) any legitimate Chromium Embedded Framework component, executing the backdoor's loader stage under the umbrella of a validly signed binary. The loader disables Windows Defender by setting the DisableAntiSpyware registry value, adds itself to system autorun so it survives reboot, and attempts privilege escalation via the `runas` verb when the current user is not an administrator. The delivery site (qnwallpaper[.]keansoft[.]cn) fronts the trojanized adware download, while a Tencent Meeting URL (meeting[.]tencent[.]com) is used as a decoy landing page during the infection flow.
Once installed, ValleyRAT/Winos 4.0 behaves as a full-featured, plugin-based backdoor: it harvests keystrokes and clipboard contents, captures screenshots, can reboot or shut down the host, and downloads/loads additional malicious modules on operator command. To resist takedown it flags its own process as critical to the OS, so any attempt to forcibly terminate it triggers a Windows blue-screen-of-death rather than allowing the process to be killed cleanly. Kaspersky recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users during 2026, concentrated in China and India, consistent with an opportunistic, adware-bundled distribution model rather than narrowly targeted spear-phishing.
ValleyRAT/Winos 4.0 is the signature backdoor of the Chinese-speaking cybercrime/espionage cluster tracked as Silver Fox (aka SwimSnake, The Great Thief of Valley, UTG-Q-1000, Void Arachne), an evolution of legacy Gh0st RAT-derived tooling built around a modular plugin architecture. A leaked builder (compiled March 2025) exposed the backdoor's internals: 19 paired 32/64-bit main plugins covering beaconing, keylogging, audio/video/screen capture, remote terminal, file/registry management, scheduled-task persistence, proxy tunneling, a DDoS stress-test module, and credential theft from Chinese applications (QQ, WeChat, Telegram) and browsers. A separate Driver Plugin embeds a 64-bit kernel-mode rootkit derived from the public 'Hidden' rootkit project that hides registry keys/files, protects the malware's process, injects shellcode via APC queuing, and force-deletes 50+ competing EDR/AV drivers (including Kaspersky, Qihoo 360, Huorong, and Tencent security products) at startup. Related Silver Fox campaigns documented in the same period show the group's rapid tooling evolution: abuse of a Microsoft-signed WatchDog Antimalware driver (amsdk.sys) to kill PP/PPL-protected security processes (BYOVD), a three-driver BYOVD chain (adding BootRepair.sys and EnPortv.sys) against a Japanese industrial manufacturer via trusted-software hijacking (ConvertToPDF.exe/PDFDirect.exe sideloading), and tax-themed phishing lures against Indian and Russian organizations that deliver a new ValleyRAT plugin loading a previously undocumented Python-based backdoor, ABCDoor. This QN Wallpaper campaign reuses the DLL-sideload technique previously seen in a 2025 PNGPlug loader campaign that also abused libcef.dll, suggesting shared tooling/infrastructure across the actor's distribution chains.
Target sectors: consumer, government administration, finance, health, manufacturing
Target regions: china, india, russia, japan, malaysia, taiwan
Timeline
- The ValleyRAT/Winos 4.0 32-bit PE builder used across the malware family is compiled; ~85% of ~6,000 later-observed samples emerge within six months of this build, per Check Point Research.
- Silver Fox is observed exploiting a Microsoft-signed WatchDog Antimalware driver (amsdk.sys) to terminate PP/PPL-protected security processes before deploying ValleyRAT.
- Kaspersky detects a wave of tax-authority-themed phishing emails targeting Indian users that deliver ValleyRAT, attributed to Silver Fox.
- A similar tax-themed campaign begins targeting Russian organizations; the delivered ValleyRAT plugin loads a previously undocumented Python-based backdoor codenamed ABCDoor.
- The ABCDoor/tax-themed India-Russia campaign is publicly reported.
- Cato Networks documents Silver Fox targeting a Japanese industrial manufacturer with an updated attack chain: two new DLL-sideloading hosts (ConvertToPDF.exe, PDFDirect.exe) and two new kernel drivers (BootRepair.sys, EnPortv.sys) used to disable security tooling before deploying ValleyRAT.
- Kaspersky/The Hacker News report the QN Wallpaper-disguised ValleyRAT campaign: a signed QnWallpaper.exe sideloads a malicious libcef.dll, disables Windows Defender, and installs the ValleyRAT backdoor; 100,000+ detections and 1,500+ unique victims recorded in 2026, mostly in China and India.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195, T1204, T1129, T1547, T1548, T1574, T1685, T1112, T1055, T1057