Attackers distribute a well-known backdoor under the guise of adware, using techniques such as DLL sideloading to bypass security controls. The malware is designed to persist on a device and deliver the ValleyRAT backdoor. It achieves this by deploying a modified Chinese desktop wallpaper management tool called QN Wallpaper, which is used to carry out DLL sideloading. The attackers use various file names and suffixes to deploy different actions, including installing legitimate applications such as DingTalk and Google Chrome, or opening a URL that leads to a malicious download.
The malware also disables Windows Defender and launches the QN Wallpaper module, which in turn launches another adware module called QnwPlayer. These modules have dependencies on a malicious library called a malicious library, which contains functions that are put into an infinite sleep. The malware checks if the current user belongs to the Administrators group and then calls a function that contains the actual malicious code. This code ensures persistence at startup by adding a file extension association and dropping a file in the Startup directory.[/subscribe_to_unlock_form]
Attackers distribute a well-known backdoor under the guise of adware, using techniques such as DLL sideloading to bypass security controls. The malware is designed to persist on a device and deliver the ValleyRAT backdoor. It achieves this by deploying a modified Chinese desktop wallpaper management tool called QN Wallpaper, which is used to carry out DLL sideloading. The attackers use various file names and suffixes to deploy different actions, including installing legitimate applications such as DingTalk and Google Chrome, or opening a URL that leads to a malicious download.
The malware also disables Windows Defender and launches the QN Wallpaper module, which in turn launches another adware module called QnwPlayer. These modules have dependencies on a malicious library called a malicious library, which contains functions that are put into an infinite sleep. The malware checks if the current user belongs to the Administrators group and then calls a function that contains the actual malicious code. This code ensures persistence at startup by adding a file extension association and dropping a file in the Startup directory.[emaillocker id="1283"]
This campaign delivers a high-risk threat, as it uses techniques to evade security controls and deliver a backdoor onto a device. The attackers may have chosen this distribution method because the adware was signed by the developer, making it more difficult for users to detect. The malware is designed to divert user attention away from its malicious functionality, making it challenging to identify.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.006 | Command and Scripting Interpreter | Python |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Defence Evasion | T1055 | Process Injection | - |
| Defence Evasion | T1574.001 | Hijack Execution Flow | DLL |
| Credential access | T1056.001 | Input Capture | Keylogging |
| Collection | T1113 | Screen Capture | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Execution | E1204 | User Execution |
| Command & Control | E1105 | Ingress Tool Transfer |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
The following reports contain further technical details:
[/emaillocker]