Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India
Brief
Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware delivery.
The installer changes its visible behavior according to its filename. One version installs a collaboration app, another installs a browser, and a third opens a meeting-download page.
Those harmless-looking actions can keep a victim occupied while the malicious components are placed on the machine. Researchers at Securelist identified the activity after an apparent adware sample generated suspicious network traffic.
Securelist said in a report shared with Cyber Security News (CSN) that they found its advertising feature did not work at all.
Instead, it started a hidden chain that launched ValleyRAT through a modified wallpaper-management application.
