1. Description
ValleyRAT is a Windows-based remote access malware capable of maintaining access to compromised systems while collecting information and receiving commands from a remote infrastructure.
The campaign examined here uses a modified version of QN Wallpaper as part of the infection chain. Rather than relying on an obviously malicious executable, the malware is concealed within software presented to victims as legitimate adware or utility software.
A key execution technique in the campaign is DLL side-loading, where a legitimate application loads a malicious libcef.dll. This allows the malicious component to execute in the context of the QN Wallpaper software.
2. Technical Description
The infection chain combines several techniques to establish and maintain control over the endpoint:
- Modified QN Wallpaper packages are used to distribute the malware.
-
QN Wallpaper components load a malicious
libcef.dll. -
QnWallpaper.exeandQnwPlayer.exeare associated with the DLL-loading process. - The malware can establish startup persistence.
- Registry-based attempts are made to weaken Windows Defender protection.
- Payload DLLs are encrypted and selected according to the host process.
- Process injection and process hollowing are used for execution and evasion.
-
svchostcan be used as an injection target. - Keyboard and clipboard information can be collected.
- Screenshots and system information can be obtained.
- C2 infrastructure provides commands and can deliver additional modules.
3. Attack Overview
The observed attack can be represented as:
Malicious/Modified Software → QN Wallpaper → DLL Side-Loading → ValleyRAT Execution → Persistence & Evasion → Information Collection → C2 Communication → Additional Commands/Modules
3.1 Initial Delivery
The malware is distributed through software presented as adware or legitimate applications. The campaign makes use of modified QN Wallpaper packages.
Reported installer names include:
-
FS_SETUP_DD_173.exe -
FS_SETUP_GG_173.exe -
FS_SETUP_HY_173.exe
These installers were associated with pages presented as downloads for applications including DingTalk, Google Chrome, and Tencent Meeting.
3.2 Malicious DLL Loading
The infection chain relies heavily on DLL side-loading.
A malicious:
libcef.dll
is loaded through QN Wallpaper components, including:
-
QnWallpaper.exe -
QnwPlayer.exe
This technique allows malicious code to execute through an application that may initially appear legitimate.
3.3 Persistence
The malware can establish persistence using mechanisms including:
- Startup/autorun behavior
- Startup folder placement
- File-extension associations
- QN Wallpaper itself may also be configured to start automatically.
3.4 Defense Evasion
The malware attempts to interfere with Windows security controls through the:
DisableAntiSpyware
registry mechanism.
The malware can also check whether the current user has administrator privileges and may use runas when elevation is required.
3.5 Process Injection and Hollowing
ValleyRAT can inject malicious code into processes such as:
svchost
Process hollowing is also used to execute additional code while making analysis and detection more difficult.
The malware additionally contains resilience mechanisms that can allow it to restart following an unexpected exception.
3.6 Information Collection
The malware has capabilities for collecting information from the compromised endpoint, including:
- Keystrokes
- Clipboard contents
- Focused window information
- Screenshots
- Hostname
- IP addresses
- Windows version
- CPU information
- Available disk space
- Graphics adapter information
- System language
- System directory
- System architecture/bitness
- User idle time
Collected information can be stored locally before further processing or transmission.
3.7 Command and Control
The malware configuration contains information related to its C2 infrastructure, including:
- C2 address
- Port
- Communication protocol
The configuration is described as being processed/reversed before use.
Reported remote capabilities include:
- System reboot
- System shutdown
- Screenshot capture
- Log wiping
- C2 configuration updates
- Downloading additional modules
Additional payloads may be obtained from C2 infrastructure or an external URL.
3. Attack Overview
The observed attack can be represented as:
Malicious/Modified Software → QN Wallpaper → DLL Side-Loading → ValleyRAT Execution → Persistence & Evasion → Information Collection → C2 Communication → Additional Commands/Modules
3.1 Initial Delivery
The malware is distributed through software presented as adware or legitimate applications. The campaign makes use of modified QN Wallpaper packages.
Reported installer names include:
-
FS_SETUP_DD_173.exe -
FS_SETUP_GG_173.exe -
FS_SETUP_HY_173.exe
These installers were associated with pages presented as downloads for applications including DingTalk, Google Chrome, and Tencent Meeting.
3.2 Malicious DLL Loading
The infection chain relies heavily on DLL side-loading.
A malicious:
libcef.dll
is loaded through QN Wallpaper components, including:
-
QnWallpaper.exe -
QnwPlayer.exe
This technique allows malicious code to execute through an application that may initially appear legitimate.
3.3 Persistence
The malware can establish persistence using mechanisms including:
- Startup/autorun behavior
- Startup folder placement
- File-extension associations
- QN Wallpaper itself may also be configured to start automatically.
3.4 Defense Evasion
The malware attempts to interfere with Windows security controls through the:
DisableAntiSpyware
registry mechanism.
The malware can also check whether the current user has administrator privileges and may use runas when elevation is required.
3.5 Process Injection and Hollowing
ValleyRAT can inject malicious code into processes such as:
svchost
Process hollowing is also used to execute additional code while making analysis and detection more difficult.
The malware additionally contains resilience mechanisms that can allow it to restart following an unexpected exception.
3.6 Information Collection
The malware has capabilities for collecting information from the compromised endpoint, including:
- Keystrokes
- Clipboard contents
- Focused window information
- Screenshots
- Hostname
- IP addresses
- Windows version
- CPU information
- Available disk space
- Graphics adapter information
- System language
- System directory
- System architecture/bitness
- User idle time
Collected information can be stored locally before further processing or transmission.
3.7 Command and Control
The malware configuration contains information related to its C2 infrastructure, including:
- C2 address
- Port
- Communication protocol
The configuration is described as being processed/reversed before use.
Reported remote capabilities include:
- System reboot
- System shutdown
- Screenshot capture
- Log wiping
- C2 configuration updates
- Downloading additional modules
Additional payloads may be obtained from C2 infrastructure or an external URL.
5. Indicators of CompromiseThe following indicators were present in the provided IOC dataset.
5.1 File Hashes
MD5
c24e99f9437feacaa63766a3cde3fe3d 7ad1e3ef4e6d9d636c9e7e967733850e 96b4c1d0683dce22bd3223e1e40689c1 9b86d3ab6cef15c633933fbbeab39c0a edfdc30cbd85879776b8f735ea7de1f1 07ddbbe2c71c45577a7a4fbcdba0df91 48826d5ca845979d2e6ebd66dc1aae90 6c158c0f8e029342192d4f0d72e102b7 9a71d6a41cd258b9e89cdc5fc224de73 8a626d844943da3456b044f38deae3a2
SHA-256
ecb49d10339b90d079e06e50470ae1c42764158ed1489c9cec31102a852cd6d1 3bca5c3a64dfaae07098bccae2edb27a00016a0c8e9b3d9658a47fdbe76320b9 51075af59f6696d5dc5446ba39fabfd0022628cdcfa41c80e7cb66e3bf4ee55d b1e06a424f2e7e3b9a5bf676665bd14bc39785fbc48cfdcc54ab63c574de0b01 7565913f7c6276954c7aa48013139838e11735fcca3b9e461a2ae9a2f468bc62 40c2bb077c6c2d6633956ccc561f2dcb161b73988638a65a06b103a4ba90b081 1c9381c675e083c80603e7cf5754275a50228b048e53b0b5c0ff5a2d8708dfdc d9ed8c718d652d6996525eda7aba7ffaee46bac1d824614952cebf67f4ed9f81
Not Identified
Not identified
5.2 File Names / Paths
libcef.dll QnWallpeper.exe QnwPlayer.exe 7z.dll 7z.exe QnWallpaper.exe Nedca.exe PeLoader
5.3 Network Indicators
IP Addresses
| IP Address | Ports |
|---|---|
103.45.66.18 | 441, 442, 443 |
192.253.225.173 | 6666, 8888 |
Domain
qnwallpaper.keansoft.cn
URLs
https://qnwallpaper.keansoft.cn/ https://xtraining.kaspersky.com/?icid=gl_sl_xtr-sale_sm-team_be9b0eac57f28846
The second URL is retained because it was present in the supplied IOC sheet. Its inclusion in that dataset alone should not be interpreted as evidence that the destination is malicious.
6. Potential ImpactA successful ValleyRAT infection could result in:
- Sensitive information exposure through clipboard and keystroke collection.
- Credential/session exposure from captured user activity.
- Privacy compromise through screenshot and focused-window monitoring.
- Persistent endpoint access through startup mechanisms.
- Reduced endpoint protection if security settings are successfully modified.
- Remote system control through C2 commands.
- Additional malware deployment through downloaded modules.
- Further compromise if stolen information is used for subsequent attacks.
7.1 Immediate Actions
- Search endpoints for the supplied IOCs, particularly the identified DLLs, executables, hashes, domain, and IP addresses.
-
Investigate unexpected instances of
QnWallpaper.exeorQnwPlayer.exe. -
Check for suspicious
libcef.dllfiles located within QN Wallpaper-related directories. - Review Windows startup locations and file-association changes.
-
Investigate suspicious registry modifications involving
DisableAntiSpyware. -
Examine unusual process relationships involving
svchost.exe. - Review network connections to the supplied IP addresses and domain.
- Isolate confirmed or strongly suspected infected systems.
- Preserve relevant forensic evidence before remediation where incident-response procedures require it.
- Reset potentially exposed credentials after confirming compromise.
7.2 Preventive Actions
- Deploy endpoint detection capable of identifying DLL side-loading and process hollowing.
- Monitor abnormal child-parent relationships involving legitimate Windows processes.
- Restrict installation of unapproved software and applications obtained from unofficial sources.
- Enable tamper protection and centrally managed endpoint security controls.
- Monitor modifications to security-related registry keys.
- Apply application allowlisting where practical.
- Monitor unusual outbound connections from desktop applications.
- Use behavioral detections in addition to static IOC matching.
- Keep operating systems and security products updated.
- Conduct user awareness training around suspicious software installers and fake download pages.
The ValleyRAT campaign demonstrates how malware operators can hide remote-access capabilities behind software that appears legitimate to the victim. The combination of modified QN Wallpaper software, DLL side-loading, encrypted payloads, persistence, process hollowing, information collection, and C2-based control creates a multi-stage compromise chain.
The supplied IOC dataset provides multiple opportunities for detection across endpoint, registry, process, file-system, and network telemetry. However, IOC matching alone may not be sufficient because malware infrastructure and filenames can change. Behavioral detections for DLL side-loading, suspicious process injection, security-control modification, startup persistence, and abnormal C2 activity should therefore be used alongside the supplied indicators.
Securelist's attribution to Silver Fox should be treated as the source's assessment rather than independently verified attribution.