ValleyRAT Malware Sneaks In Through Signed Adware That People Exclude From Antivirus Scans

ValleyRAT Malware Sneaks In Through Signed Adware That People Exclude From Antivirus Scans

A backdoor called ValleyRAT is hiding inside digitally signed adware, and users are being tricked into marking it as safe in their antivirus, giving attackers remote control.

Security researchers are warning about a dangerous distribution tactic for ValleyRAT, a type of malicious software known as a remote access trojan, or RAT. A RAT is a program that lets an attacker secretly take control of a computer from far away, often to steal files, capture passwords or watch what the victim types. In this campaign, ValleyRAT is not arriving as a suspicious file that antivirus tools would immediately block. Instead, it is hidden inside what looks like ordinary adware, software that shows unwanted advertisements and is often treated as a nuisance rather than a serious threat. To make matters worse, the adware carries a valid digital signature, a kind of electronic stamp that normally tells you the software comes from a known publisher and has not been changed since it was signed. Because the package seems legitimate, many users lower their guard.

The most troubling part of this attack is that the victims themselves perform the crucial step that lets the malware run. Antivirus programs often flag adware as a potentially unwanted application and may block or quarantine it. To keep using the adware they think they want, users are told to add the program to the antivirus exclusion list. In plain language, an exclusion list is a set of files or folders that the antivirus software is ordered to ignore completely. When a user adds the signed adware to this list, they are effectively telling the security tool: do not scan this, do not block it, do not warn me about it again. The hidden ValleyRAT backdoor then has free rein, with no antivirus barrier left to stop it.

A backdoor is a secret way into a system that bypasses normal security checks. Once ValleyRAT is active, the attacker can use it as a persistent channel to the infected computer. This can include downloading additional malware, stealing saved browser passwords, taking screenshots, recording keystrokes or even uploading and running arbitrary commands. For a home user, that might mean stolen online banking credentials or hijacked social media accounts. For a website owner or an IT administrator, the stakes are much higher. A compromised work computer can expose the login details for content management systems, hosting control panels, DNS settings or cloud services. If an attacker gets those credentials, they can deface a website, inject malicious code into web pages, redirect visitors to phishing pages or use the hosting account to send spam and host malware.

Why would anyone add adware to an antivirus exclusion list in the first place? Often it is because the adware promises a useful feature, such as a free video downloader, a file converter or a system optimizer. Some users become frustrated when their antivirus repeatedly flags the program and decide to silence the warnings rather than uninstall the software. Attackers exploit this impatience. They package ValleyRAT inside a program that users actively want to keep, then provide instructions on forums or in pop-up windows that tell the user to whitelist the entire folder. The digital signature makes the instructions seem more trustworthy, because many people believe that a signed file is automatically safe. In reality, a digital signature only confirms the file has not been modified after signing and that the signer exists. It does not guarantee that the signer is honest or that the software contains no hidden functions.

The practical impact for websites and online businesses is direct. If the computer you use to manage your website becomes infected with ValleyRAT, the attacker can steal your administrative login and quietly take over the site. They might leave the visible pages unchanged while injecting hidden links or malware downloads for visitors, damaging your reputation and search ranking without you noticing. A clean, malware-free administrative device is the first line of defense for any website owner. Beyond that, hosting providers with built-in security monitoring can detect and block many server-side attacks even if a local machine is compromised. For example, AEU Hosting's managed WordPress platform includes server-side malware scanning and automatic patching, which adds a second layer of protection for the website itself, while the site owner focuses on keeping their own computer clean with antivirus and careful exclusion management.

The simplest way to avoid falling for this trick is to never add any file or folder to your antivirus exclusion list unless you are completely certain what it is and where it came from. If a program keeps getting flagged as adware, the safest response is to uninstall it rather than teach the antivirus to ignore it. Download software only from the official developer's website or a trusted app store, and always check that the digital signature is valid and issued to the company you expect. Keep your antivirus real-time protection turned on, and periodically review the exclusion list to see if anything has been added without your knowledge. If you find a suspicious exclusion, remove it and run a full system scan immediately.

How to Protect Yourself

  1. Never add a file or folder to your antivirus exclusion list unless you are absolutely certain it is safe and you personally installed it from a trusted source.
  2. If your antivirus keeps warning you about a program, uninstall that program instead of telling the antivirus to ignore it.
  3. Download software only from the official developer's website or a trusted app store, never from random pop-up ads or third-party download sites.
  4. Check the digital signature of any installer by right-clicking the file, choosing Properties, then looking at the Digital Signatures tab to confirm it is valid and from a known publisher.
  5. Review your antivirus exclusion list regularly and remove any entries you did not add yourself, then run a full system scan.

Related AEU services

  • AEU-I IT and security consulting