You Whitelisted the Malware Yourself
your antivirus warned you about an annoying wallpaper app. you told it to stop complaining. that was the attack.
this is activity kaspersky links to the china-nexus group silver fox, and their latest trick is quietly brilliant. they hid a full-control backdoor, valleyrat, also known as winos 4.0, inside a real piece of software almost nobody takes seriously. adware. specifically a modified version of qn wallpaper, a genuine chinese desktop-wallpaper tool that in its normal form just bundles junk apps and throws ad banners at you.
think about how most people treat adware. it is merely annoying more than anything. it trips your antivirus, you get irritated at the false-positive nag, and most people just do the convenient thing. add it to the exclusion list so the scanner stops whining about it. and that is the play silver fox is exploiting. if you whitelist the annoying wallpaper app, you may have personally waved the backdoor hidden inside it right past your own defenses.
the technical move underneath is called dll sideloading. instead of running as its own suspicious program, a legitimately signed qn wallpaper executable becomes the trusted host for loading a malicious dll, which leads into the valleyrat chain. the signature gives the whole chain a layer of inherited trust. the executable itself was legitimately signed, giving the chain another layer of inherited trust. the installer even dresses up as dingtalk, chrome, or tencent meeting depending on the filename. every layer is built to look like something you likely already trust.
here is the detail i love, because it is how they got caught. a customer sent the file to kaspersky asking them to classify it as adware. it looked like adware. but in the malicious sample they analyzed, the advertising functionality never actually ran correctly. the ad banners, the whole reason adware exists, stayed inert while something else quietly kicked off in the background. the disguise was too good. real adware is greedy and wants to show you ads. this thing did not care about ads at all.
once it is in, valleyrat is not a nuisance. it is total ownership. keylogging, screenshots, data theft, and the ability to pull down more modules on command. it even flips a registry setting to disable windows built-in anti-spyware. the wallpaper app was the costume. surveillance was the job.
across all of 2026, kaspersky logged more than 100,000 detections of valleyrat and related malware, hitting over 1,500 unique users, mostly in china and india. but that is the whole year of valleyrat activity, not this one campaign. this specific qn wallpaper case is built on a single submitted installer, with no victim count attached. the group is clearly prolific, but do not let anyone tell you 100,000 machines ran this wallpaper trick.
the real lesson is about a blind spot in how we think about threats. we sort software into dangerous and harmless, and we relax the moment something lands in the harmless pile. adware is the perfect trojan horse precisely because it is beneath suspicion. it is supposed to be annoying, so annoying is where the guard drops.
silver fox did not need to rely solely on technically defeating your antivirus. they exploited the trust users place in exclusions, signed software, and familiar applications, then let those decisions help carry the malware through.
the takeaway kaspersky keeps repeating is worth internalizing. the exclusion list is not a convenience feature. it is a hole you punch in your own security, by hand, and the attacker is counting on you to punch it.
the most dangerous malware does not look dangerous. it looks like the something you decided to stop worrying about.