ValleyRAT is spreading disguised as adware

Reported 31 Aug 2026 by otx · Severity: medium

Attackers are distributing the ValleyRAT backdoor disguised as legitimate Chinese adware called QN Wallpaper. The malicious installer deploys a modified version of the wallpaper management tool and uses DLL sideloading techniques to execute malicious code under a signed process.