ValleyRAT in Signed QN Wallpaper Installers — Sandbox Flags the Keylogging Payload of a Silver Fox Campaign (2026-09-08 CISO Daily Digest)
The 2026-09-08 CISO Daily Digest reported a ValleyRAT (Winos 4.0) campaign documented by Kaspersky that delivers the remote-access trojan through trojanized copies of the legitimate Chinese wallpaper/adware app QN Wallpaper, offered via fake installers for Alibaba's DingTalk, Tencent meeting software and Google Chrome. Because the carrier app carries a valid code-signing signature and users commonly add such adware to antivirus exclusions, the trojanized installer leans on DLL sideloading to run the RAT with a much higher chance of success; Kaspersky counted over 100,000 ValleyRAT-related detections in 2026 affecting at least 1,500 users, concentrated in China and India, and attributes the activity to the China-linked Silver Fox group. ValleyRAT is a plugin-based remote-access trojan whose capabilities include keystroke logging and remote control — the kind of 'input capture' behavior a signed-but-hostile installer ends up delivering to the endpoint. This demo safely reproduces that payload-behavior stage: the malicious sample (malicious-payload.sh, plus a Windows .cmd companion) writes a local keylog marker file (./keylog.txt, '[demo] keys would be logged here') as a stand-in for the RAT's keystroke capture, then opens the Calculator as its only visible impact — no real keys are captured, nothing is exfiltrated, no network contact, no destruction; the clean control sample (clean-payload.sh) has the attack sequence removed and opens nothing. MetaDefender Sandbox detonates the sample in an isolated environment, observes the keylogging / input-capture sequence, and reports the behavior with indicators before a real ValleyRAT payload could operate on a host (MITRE ATT&CK T1056.001 — Input Capture: Keylogging).
Attack Technique
ValleyRAT (Winos 4.0) delivered via trojanized, still code-signed QN Wallpaper adware installers masquerading as DingTalk / Tencent Meeting / Chrome (DLL sideloading; documented by Kaspersky, attributed to China-linked Silver Fox) — payload-stage keystroke logging observed in an isolated sandbox (T1056.001)
MITRE ATT&CK
T1056.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗