Fake Wallpaper App Used to Sneak ValleyRAT Backdoor Past Antivirus
Security researchers at Kaspersky have uncovered a campaign in which the threat group known as Silver Fox is distributing the ValleyRAT backdoor disguised as QN Wallpaper, a legitimate Chinese desktop customisation tool. Because the fake app carries a valid digital signature, it appears trustworthy, and many users end up adding it to their antivirus exclusion lists — believing this improves performance or avoids false positives.
Once excluded from scanning, the malicious software runs the ValleyRAT backdoor under the guise of a trusted process, allowing attackers to operate largely undetected on infected systems. This technique highlights a growing trend where cybercriminals exploit user trust in signed software and common security habits, such as exclusion lists, to bypass otherwise effective defences.
While this campaign currently appears focused on Chinese-language software distribution, the underlying technique — abusing digital signatures and antivirus exclusions — is a tactic that could easily be adapted for use against businesses elsewhere, including Australian organisations that download utility or customisation software from unofficial sources.