
Findings and evidence
A file initially classified as adware led Kaspersky researchers to a ValleyRAT delivery chain after they noticed unexpected network activity. The report documents a modified wallpaper application and distinguishes its apparent function from the backdoor behavior.
Why it matters
Triage labels should remain revisable. Compare claimed functionality with observed behavior, preserve the original installer and record why the evidence changed the working hypothesis.
Scope and limits
This case does not make all advertising-supported software malicious. The finding depends on the particular modified files and their behavior.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-08-31. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.