Signed Adware Became a ValleyRAT Delivery Path

Kaspersky says a sample it first classified as adware was really a signed installer chain that delivered the ValleyRAT backdoor. The lure was a familiar one: software users and security tools are already inclined to trust, and sometimes exclude, so the sample could move through those guardrails. Inside the package, the installer drops QN Wallpaper, adds it to autorun, disables Microsoft Defender through the DisableAntiSpyware registry key, and then abuses DLL sideloading so a malicious library runs under a signed-looking process. That means the payload arrives as allowed software, not as a loud standalone malware file. For Windows teams that rely on signed-software allowlists or user-managed exclusions, the exposure sits in the trust model itself. If a benign-looking, signed utility can be turned into the carrier, then exclusions meant to reduce friction can also become the path that lets a backdoor blend in and persist.

Part of the PlainSec briefing for 2026-08-31

Every edition of this story: Signed Adware Became a ValleyRAT Delivery Path

Sources