ValleyRAT masquerading as adware
August 31, 2026 · Kaspersky (Securelist) · Severity: HIGH
Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices.

Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked.
Some time ago, a client asked us to analyze a file with the MD5 hash c24e99f9437feacaa63766a3cde3fe3d and add it to our detection database. We initially classified it as adware, but a cursory analysis turned up suspicious network activity, which prompted us to dig deeper. It turned out the sample did far more than serve ads. In fact, its advertising functionality doesn’t even work; instead, it triggers an infection chain that delivers the ValleyRAT backdoor.
Malicious installer
The file the client shared with us turned out to be an installer that performed different actions depending on the two-letter suffix used in the file name, positioned just before the numeric string.
| Installer name | What it does |
| FS_SETUP_DD_173.exe | Installs DingTalk, a workplace collaboration platform |
| FS_SETUP_GG_173.exe | Installs Google Chrome |
| FS_SETUP_HY_173.exe | Opens hxxps://meeting[.]tencent[.]com/download/ |
These actions are most likely designed to divert the user’s attention away from the sample’s malicious functionality. Regardless of the file name, the installer deploys a modified Chinese desktop wallpaper management tool called QN Wallpaper (hxxps://qnwallpaper[.]keansoft[.]cn/) and adds it to the registry’s autorun entries.
The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user. In this case, however, the attackers use it to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL.
The QN Wallpaper modules, along with the malicious components, are unpacked to C:\Program Files\QNWallpaper\5.4.0.1662\<random string of letters and digits>. The following files are saved in that directory:
| File name | MD5 | Purpose |
| 1.zip | 7ad1e3ef4e6d9d636c9e7e967733850e | Archive containing the adware files QnWallpeper.exe and QnwPlayer.exe, along with the modules needed to run them |
| 7z.dll | 96b4c1d0683dce22bd3223e1e40689c1 | 7z archiver library |
| 7z.exe | 9b86d3ab6cef15c633933fbbeab39c0a | Archiver |
| chrome_elf.dll | edfdc30cbd85879776b8f735ea7de1f1 | Library used to launch Electron-based applications |
| libcef.dll | 07ddbbe2c71c45577a7a4fbcdba0df91 | Malicious library |
| PeLoader | 48826d5ca845979d2e6ebd66dc1aae90 | File containing the encrypted backdoor |
| QnWallpaper.exe | 6c158c0f8e029342192d4f0d72e102b7 | Adware module |
| QnwPlayer.exe | 9a71d6a41cd258b9e89cdc5fc224de73 | Adware module |
| <random string of letters and digits>Nedca.exe | c24e99f9437feacaa63766a3cde3fe3d | Malicious installer copy |
After unpacking, the installer uses the DisableAntiSpyware registry key to disable Windows Defender and then launches QnWallpaper.exe.
DLL Sideloading via libcef.dll
QnWallpaper.exe has dependencies in libcef.dll, so this library gets loaded when the process starts. QnWallpaper.exe also launches QnwPlayer.exe, which likewise calls libcef.dll.
QnWallpaper and QnwPlayer won’t actually function correctly, because the functions exported from libcef.dll are put into an infinite sleep. However, in case that sleep is ever interrupted, the attackers have implemented a function that loads all the necessary functions from the original library into memory, provided it can locate that library on the system.



