Threat Advisory

QN Wallpaper Distributes ValleyRAT Backdoor via DLL Sideload

Threat: Malware
Targeted Region: China, India
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers distribute a well-known backdoor under the guise of adware, using techniques such as DLL sideloading to bypass security controls. The malware is designed to persist on a device and deliver the ValleyRAT backdoor. It achieves this by deploying a modified Chinese desktop wallpaper management tool called QN Wallpaper, which is used to carry out DLL sideloading. The attackers use various file names and suffixes to deploy different actions, including installing legitimate applications such as DingTalk and Google Chrome, or opening a URL that leads to a malicious download.

The malware also disables Windows Defender and launches the QN Wallpaper module, which in turn launches another adware module called QnwPlayer. These modules have dependencies on a malicious library called a malicious library, which contains functions that are put into an infinite sleep. The malware checks if the current user belongs to the Administrators group and then calls a function that contains the actual malicious code. This code ensures persistence at startup by adding a file extension association and dropping a file in the Startup directory.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Attackers distribute a well-known backdoor under the guise of adware, using techniques such as DLL sideloading to bypass security controls. The malware is designed to persist on a device and deliver the ValleyRAT backdoor. It achieves this by deploying a modified Chinese desktop wallpaper management tool called QN Wallpaper, which is used to carry out DLL sideloading. The attackers use various file names and suffixes to deploy different actions, including installing legitimate applications such as DingTalk and Google Chrome, or opening a URL that leads to a malicious download.

The malware also disables Windows Defender and launches the QN Wallpaper module, which in turn launches another adware module called QnwPlayer. These modules have dependencies on a malicious library called a malicious library, which contains functions that are put into an infinite sleep. The malware checks if the current user belongs to the Administrators group and then calls a function that contains the actual malicious code. This code ensures persistence at startup by adding a file extension association and dropping a file in the Startup directory.[emaillocker id="1283"]

This campaign delivers a high-risk threat, as it uses techniques to evade security controls and deliver a backdoor onto a device. The attackers may have chosen this distribution method because the adware was signed by the developer, making it more difficult for users to detect. The malware is designed to divert user attention away from its malicious functionality, making it challenging to identify.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.006 Command and Scripting Interpreter Python
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Defence Evasion T1055 Process Injection -
Defence Evasion T1574.001 Hijack Execution Flow DLL
Credential access T1056.001 Input Capture Keylogging
Collection T1113 Screen Capture -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Persistence F0012 Registry Run Keys / Startup Folder
Anti-Static Analysis E1027 Obfuscated Files or Information
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Execution E1204 User Execution
Command & Control E1105 Ingress Tool Transfer
Defense Evasion F0004 Disable or Evade Security Tools

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu