ThreatBeaconXThreatBeaconXSubscribe
HighThreat Research · 13 min read

ValleyRAT Campaign Abuses QN Wallpaper to Establish Persistent Windows Access

ValleyRAT is a Windows-based remote access malware capable of maintaining access to compromised systems while collecting information and receiving commands from a remote infrastructure. The campaign examined here uses a modified version of QN Wallpaper as part of the infection chain. Rather than relying on an obviously malicious executable, the malware is concealed within software presented to victims as legitimate adware or utility software. A key execution technique in the campaign is DLL side-loading, where a legitimate application loads a malicious libcef.dll, allowing the malicious component to execute in the context of the QN Wallpaper software.

Written by Vedanabhatla Sai Swetha·Published Sep 6, 2026

1. Description

ValleyRAT is a Windows-based remote access malware capable of maintaining access to compromised systems while collecting information and receiving commands from a remote infrastructure.

The campaign examined here uses a modified version of QN Wallpaper as part of the infection chain. Rather than relying on an obviously malicious executable, the malware is concealed within software presented to victims as legitimate adware or utility software.

A key execution technique in the campaign is DLL side-loading, where a legitimate application loads a malicious libcef.dll. This allows the malicious component to execute in the context of the QN Wallpaper software.

2. Technical Description

The infection chain combines several techniques to establish and maintain control over the endpoint:

  • Modified QN Wallpaper packages are used to distribute the malware.
  • QN Wallpaper components load a malicious libcef.dll.
  • QnWallpaper.exe and QnwPlayer.exe are associated with the DLL-loading process.
  • The malware can establish startup persistence.
  • Registry-based attempts are made to weaken Windows Defender protection.
  • Payload DLLs are encrypted and selected according to the host process.
  • Process injection and process hollowing are used for execution and evasion.
  • svchost can be used as an injection target.
  • Keyboard and clipboard information can be collected.
  • Screenshots and system information can be obtained.
  • C2 infrastructure provides commands and can deliver additional modules.

3. Attack Overview

The observed attack can be represented as:

Malicious/Modified Software → QN Wallpaper → DLL Side-Loading → ValleyRAT Execution → Persistence & Evasion → Information Collection → C2 Communication → Additional Commands/Modules

3.1 Initial Delivery

The malware is distributed through software presented as adware or legitimate applications. The campaign makes use of modified QN Wallpaper packages.

Reported installer names include:

  • FS_SETUP_DD_173.exe
  • FS_SETUP_GG_173.exe
  • FS_SETUP_HY_173.exe

These installers were associated with pages presented as downloads for applications including DingTalk, Google Chrome, and Tencent Meeting.

3.2 Malicious DLL Loading

The infection chain relies heavily on DLL side-loading.

A malicious:

libcef.dll

is loaded through QN Wallpaper components, including:

  • QnWallpaper.exe
  • QnwPlayer.exe

This technique allows malicious code to execute through an application that may initially appear legitimate.

3.3 Persistence

The malware can establish persistence using mechanisms including:

  • Startup/autorun behavior
  • Startup folder placement
  • File-extension associations
  • QN Wallpaper itself may also be configured to start automatically.

3.4 Defense Evasion

The malware attempts to interfere with Windows security controls through the:

DisableAntiSpyware

registry mechanism.

The malware can also check whether the current user has administrator privileges and may use runas when elevation is required.

3.5 Process Injection and Hollowing

ValleyRAT can inject malicious code into processes such as:

svchost

Process hollowing is also used to execute additional code while making analysis and detection more difficult.

The malware additionally contains resilience mechanisms that can allow it to restart following an unexpected exception.

3.6 Information Collection

The malware has capabilities for collecting information from the compromised endpoint, including:

  • Keystrokes
  • Clipboard contents
  • Focused window information
  • Screenshots
  • Hostname
  • IP addresses
  • Windows version
  • CPU information
  • Available disk space
  • Graphics adapter information
  • System language
  • System directory
  • System architecture/bitness
  • User idle time

Collected information can be stored locally before further processing or transmission.

3.7 Command and Control

The malware configuration contains information related to its C2 infrastructure, including:

  • C2 address
  • Port
  • Communication protocol

The configuration is described as being processed/reversed before use.

Reported remote capabilities include:

  • System reboot
  • System shutdown
  • Screenshot capture
  • Log wiping
  • C2 configuration updates
  • Downloading additional modules

Additional payloads may be obtained from C2 infrastructure or an external URL.

3. Attack Overview

The observed attack can be represented as:

Malicious/Modified Software → QN Wallpaper → DLL Side-Loading → ValleyRAT Execution → Persistence & Evasion → Information Collection → C2 Communication → Additional Commands/Modules

3.1 Initial Delivery

The malware is distributed through software presented as adware or legitimate applications. The campaign makes use of modified QN Wallpaper packages.

Reported installer names include:

  • FS_SETUP_DD_173.exe
  • FS_SETUP_GG_173.exe
  • FS_SETUP_HY_173.exe

These installers were associated with pages presented as downloads for applications including DingTalk, Google Chrome, and Tencent Meeting.

3.2 Malicious DLL Loading

The infection chain relies heavily on DLL side-loading.

A malicious:

libcef.dll

is loaded through QN Wallpaper components, including:

  • QnWallpaper.exe
  • QnwPlayer.exe

This technique allows malicious code to execute through an application that may initially appear legitimate.

3.3 Persistence

The malware can establish persistence using mechanisms including:

  • Startup/autorun behavior
  • Startup folder placement
  • File-extension associations
  • QN Wallpaper itself may also be configured to start automatically.

3.4 Defense Evasion

The malware attempts to interfere with Windows security controls through the:

DisableAntiSpyware

registry mechanism.

The malware can also check whether the current user has administrator privileges and may use runas when elevation is required.

3.5 Process Injection and Hollowing

ValleyRAT can inject malicious code into processes such as:

svchost

Process hollowing is also used to execute additional code while making analysis and detection more difficult.

The malware additionally contains resilience mechanisms that can allow it to restart following an unexpected exception.

3.6 Information Collection

The malware has capabilities for collecting information from the compromised endpoint, including:

  • Keystrokes
  • Clipboard contents
  • Focused window information
  • Screenshots
  • Hostname
  • IP addresses
  • Windows version
  • CPU information
  • Available disk space
  • Graphics adapter information
  • System language
  • System directory
  • System architecture/bitness
  • User idle time

Collected information can be stored locally before further processing or transmission.

3.7 Command and Control

The malware configuration contains information related to its C2 infrastructure, including:

  • C2 address
  • Port
  • Communication protocol

The configuration is described as being processed/reversed before use.

Reported remote capabilities include:

  • System reboot
  • System shutdown
  • Screenshot capture
  • Log wiping
  • C2 configuration updates
  • Downloading additional modules

Additional payloads may be obtained from C2 infrastructure or an external URL.

5. Indicators of Compromise

The following indicators were present in the provided IOC dataset.

5.1 File Hashes

MD5

c24e99f9437feacaa63766a3cde3fe3d
7ad1e3ef4e6d9d636c9e7e967733850e
96b4c1d0683dce22bd3223e1e40689c1
9b86d3ab6cef15c633933fbbeab39c0a
edfdc30cbd85879776b8f735ea7de1f1
07ddbbe2c71c45577a7a4fbcdba0df91
48826d5ca845979d2e6ebd66dc1aae90
6c158c0f8e029342192d4f0d72e102b7
9a71d6a41cd258b9e89cdc5fc224de73
8a626d844943da3456b044f38deae3a2

SHA-256

ecb49d10339b90d079e06e50470ae1c42764158ed1489c9cec31102a852cd6d1
3bca5c3a64dfaae07098bccae2edb27a00016a0c8e9b3d9658a47fdbe76320b9
51075af59f6696d5dc5446ba39fabfd0022628cdcfa41c80e7cb66e3bf4ee55d
b1e06a424f2e7e3b9a5bf676665bd14bc39785fbc48cfdcc54ab63c574de0b01
7565913f7c6276954c7aa48013139838e11735fcca3b9e461a2ae9a2f468bc62
40c2bb077c6c2d6633956ccc561f2dcb161b73988638a65a06b103a4ba90b081
1c9381c675e083c80603e7cf5754275a50228b048e53b0b5c0ff5a2d8708dfdc
d9ed8c718d652d6996525eda7aba7ffaee46bac1d824614952cebf67f4ed9f81

Not Identified

Not identified

5.2 File Names / Paths

libcef.dll
QnWallpeper.exe
QnwPlayer.exe
7z.dll
7z.exe
QnWallpaper.exe
Nedca.exe
PeLoader

5.3 Network Indicators

IP Addresses

IP AddressPorts
103.45.66.18441, 442, 443
192.253.225.1736666, 8888

Domain

qnwallpaper.keansoft.cn

URLs

https://qnwallpaper.keansoft.cn/
https://xtraining.kaspersky.com/?icid=gl_sl_xtr-sale_sm-team_be9b0eac57f28846

The second URL is retained because it was present in the supplied IOC sheet. Its inclusion in that dataset alone should not be interpreted as evidence that the destination is malicious.

6. Potential Impact

A successful ValleyRAT infection could result in:

  • Sensitive information exposure through clipboard and keystroke collection.
  • Credential/session exposure from captured user activity.
  • Privacy compromise through screenshot and focused-window monitoring.
  • Persistent endpoint access through startup mechanisms.
  • Reduced endpoint protection if security settings are successfully modified.
  • Remote system control through C2 commands.
  • Additional malware deployment through downloaded modules.
  • Further compromise if stolen information is used for subsequent attacks.
7. Recommendations

7.1 Immediate Actions

  • Search endpoints for the supplied IOCs, particularly the identified DLLs, executables, hashes, domain, and IP addresses.
  • Investigate unexpected instances of QnWallpaper.exe or QnwPlayer.exe.
  • Check for suspicious libcef.dll files located within QN Wallpaper-related directories.
  • Review Windows startup locations and file-association changes.
  • Investigate suspicious registry modifications involving DisableAntiSpyware.
  • Examine unusual process relationships involving svchost.exe.
  • Review network connections to the supplied IP addresses and domain.
  • Isolate confirmed or strongly suspected infected systems.
  • Preserve relevant forensic evidence before remediation where incident-response procedures require it.
  • Reset potentially exposed credentials after confirming compromise.

7.2 Preventive Actions

  • Deploy endpoint detection capable of identifying DLL side-loading and process hollowing.
  • Monitor abnormal child-parent relationships involving legitimate Windows processes.
  • Restrict installation of unapproved software and applications obtained from unofficial sources.
  • Enable tamper protection and centrally managed endpoint security controls.
  • Monitor modifications to security-related registry keys.
  • Apply application allowlisting where practical.
  • Monitor unusual outbound connections from desktop applications.
  • Use behavioral detections in addition to static IOC matching.
  • Keep operating systems and security products updated.
  • Conduct user awareness training around suspicious software installers and fake download pages.
8. Conclusion

The ValleyRAT campaign demonstrates how malware operators can hide remote-access capabilities behind software that appears legitimate to the victim. The combination of modified QN Wallpaper software, DLL side-loading, encrypted payloads, persistence, process hollowing, information collection, and C2-based control creates a multi-stage compromise chain.

The supplied IOC dataset provides multiple opportunities for detection across endpoint, registry, process, file-system, and network telemetry. However, IOC matching alone may not be sufficient because malware infrastructure and filenames can change. Behavioral detections for DLL side-loading, suspicious process injection, security-control modification, startup persistence, and abnormal C2 activity should therefore be used alongside the supplied indicators.

Securelist's attribution to Silver Fox should be treated as the source's assessment rather than independently verified attribution.

MITRE ATT&CK Mapping

T1574.002 — DLL Side-LoadingT1055.012 — Process HollowingT1055 — Process InjectionT1547.001 — Registry Run Keys / Startup FolderT1112 — Modify RegistryT1059 — Command and Scripting InterpreterT1083 — File and Directory DiscoveryT1082 — System Information DiscoveryT1057 — Process DiscoveryT1113 — Screen CaptureT1056.001 — KeyloggingT1115 — Clipboard DataT1105 — Ingress Tool TransferT1071 — Application Layer ProtocolT1562.001 — Impair Defenses