Interestana
Home/News/ValleyRAT Backdoor Exploits Antivirus Exclusions Via Signed Adware
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

ValleyRAT Backdoor Exploits Antivirus Exclusions Via Signed Adware

ValleyRAT Backdoor Exploits Antivirus Exclusions Via Signed Adware

The sophisticated ValleyRAT backdoor is being distributed by a threat actor identified as Silver Fox, employing a novel tactic that leverages user trust in legitimate software and antivirus exclusion lists. This backdoor is disguised as a signed adware application, specifically a Chinese desktop wallpaper tool named QN Wallpaper. Russian cybersecurity vendor Kaspersky reported on this evolving threat, detailing how the attackers are exploiting a common user behavior: adding trusted applications to antivirus exclusion lists to prevent them from being flagged or removed. By signing the malicious adware, the threat actors imbue it with a veneer of legitimacy, making it more likely to bypass initial security checks and be accepted by users.

QN Wallpaper is a genuine desktop wallpaper application originating from China. The threat actors have embedded the ValleyRAT backdoor within this legitimate software. When a user installs QN Wallpaper, they are unknowingly installing the backdoor as well. The critical element of this attack lies in the subsequent user action. Many users, particularly those who frequently download and use utility software, create exclusion lists within their antivirus or anti-malware programs. These lists are intended to prevent the security software from interfering with the operation of applications the user deems safe or necessary. The attackers are banking on users adding the signed QN Wallpaper to these exclusion lists. Once added, the ValleyRAT backdoor operates under the guise of a trusted process, making it significantly harder for security software to detect and neutralize.

Kaspersky's analysis indicates that the ValleyRAT backdoor is designed for stealth and persistence. Its ability to hide within a signed, seemingly legitimate application and then operate under the protection of an antivirus exclusion list represents a significant challenge for cybersecurity defenses. This method bypasses traditional signature-based detection and heuristic analysis that might otherwise flag the malware. The effectiveness of this approach is amplified by the fact that users themselves are actively contributing to the malware's ability to evade detection. The implications of this attack vector are broad, potentially affecting a wide range of users who rely on antivirus software for protection but may inadvertently weaken their defenses by managing exclusion lists without thorough vetting of the software they are adding.

The threat actor Silver Fox's strategy highlights a growing trend in cyberattacks where social engineering and the exploitation of user behavior are combined with technical sophistication. The use of signed binaries, while not inherently malicious, is being weaponized by attackers to gain trust. The ValleyRAT backdoor's distribution through QN Wallpaper underscores the importance of user education regarding software installations and the management of security settings. Cybersecurity professionals are continuously developing new methods to detect such advanced persistent threats, but the human element remains a critical vulnerability that attackers are adept at exploiting. The ongoing monitoring and analysis of threats like ValleyRAT by firms such as Kaspersky are crucial for understanding and mitigating these evolving cyber risks.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next