ValleyRAT Used in Signed Chinese Adware

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, which evades detection by users who add such software to their antivirus exclusions.

Bottom line: The use of signed adware to hide malware indicates a shift in the tactics, techniques, and procedures (TTPs) of the threat actor.

What's happening: Kaspersky researcher, Christian Ehrhardt, discovered the malware was distributed via a signed Chinese adware application that was added to the antivirus exclusions of infected computers. This malware has been linked to the Silver Fox group, a known threat actor. The malware was observed running under a trusted process, allowing it to avoid detection by users who have excluded such software from their antivirus scans.

What to do: CISOs should review their antivirus exclusion lists to ensure that only trusted software is excluded from scans, and consider implementing additional security measures to detect and prevent the use of signed adware.

Source: The Hacker News