ValleyRAT Malware Hides Inside Signed Chinese Wallpaper App to Bypass Antivirus
Silver Fox is smuggling the ValleyRAT backdoor onto Windows PCs by wrapping it around QN Wallpaper, a legitimate signed program many users have already told their antivirus to trust.

Key points
- A hacking group known as Silver Fox is spreading ValleyRAT, a remote-access backdoor, by hiding it inside a real Chinese wallpaper app called QN Wallpaper.
- The malware runs under a signed, trusted process, letting it slip past antivirus software that users have set to ignore adware.
- Russian security vendor Kaspersky reported the campaign, which targets Chinese-speaking Windows users.
- The trick relies on a common user habit: adding noisy but harmless adware to antivirus exclusion lists.
- There is no formal patch here. Defence depends on reviewing exclusions and blocking the loader.
A Chinese-speaking hacking crew called Silver Fox has found a quiet way onto Windows machines. It hides its malware inside a real program that many users have already told their antivirus to leave alone.
The program is QN Wallpaper, a genuine Chinese desktop-wallpaper tool. It is signed with a valid certificate, meaning Windows treats it as coming from a known publisher. It also behaves like adware, the kind of noisy free software that pesters users with promotions, so people often add it to their antivirus exclusion list to stop the warnings.
That exclusion is the whole trick.
Once the app is trusted, Silver Fox uses it to load ValleyRAT, a backdoor that gives the attackers remote control of the machine. Because the malicious code runs under the signed, trusted process, the antivirus does not look twice.
Russian cybersecurity vendor Kaspersky described the campaign, which was first reported by The Hacker News. Kaspersky said the attackers built the disguise around the real QN Wallpaper software rather than faking it, which is what makes the certificate check pass.
What is ValleyRAT and who is behind it?
ValleyRAT is a remote access trojan, meaning malicious software that lets an attacker operate a victim's computer from afar. It can run commands, steal files, and install more malware. Silver Fox, the group linked to this campaign, has been tracked for the past two years targeting Chinese-speaking Windows users, often through fake installers and poisoned software downloads.
The group tends to go after finance, accounting and small-business users in mainland China. This latest run continues that pattern.
How does the antivirus bypass actually work?
Antivirus tools let users mark certain programs or folders as safe. It is a normal feature, meant for software that keeps triggering false alarms. Adware falls into that bucket for a lot of people. Rather than uninstall the wallpaper app, they tell the scanner to ignore it.
Silver Fox counts on that. The attackers load ValleyRAT through the signed QN Wallpaper process, so any file activity, network traffic or registry change looks like it is coming from a program the user has already approved. The scanner sees a trusted parent process and moves on.
| Element | Detail |
|---|---|
| Group | Silver Fox (China-linked) |
| Malware | ValleyRAT backdoor |
| Cover app | QN Wallpaper (signed, legitimate) |
| Target | Chinese-speaking Windows users |
| Reported by | Kaspersky |
Should ordinary users be worried?
If you are not in China and do not run Chinese desktop utilities, the direct risk is low. The broader lesson matters more. Any program you have told your antivirus to skip becomes a soft spot. If an attacker can piggyback on that program, your protection is off for that part of the system.
A quick check: open your antivirus, find the exclusions or allow list, and remove anything you no longer use or do not recognise. Uninstall adware rather than muting it.
Common questions
Is QN Wallpaper itself malicious?
No. The wallpaper application is a real product with a valid signature. Silver Fox abuses it as a delivery vehicle. The developers are not accused of wrongdoing.
How do I know if I am infected?
Look for unusual outbound network connections from the wallpaper process, unfamiliar scheduled tasks, and unexpected files in your user profile. A full scan with exclusions temporarily disabled will catch most variants.



