Counterfeit installers to system compromise: Tracking a deceptive software download campaign
released on 2026-09-02 @ 02:57:19 AM
A malware campaign uses counterfeit software-download websites impersonating trusted vendors to distribute malicious installers. The activity primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Malicious installers deploy payloads that establish persistence, disable security protections, and communicate with attacker-controlled infrastructure. The campaign employs dynamically generated installers with rotating hashes, spoofed vendor pages on .com.cn and .hl.cn domains, and randomized payload staging paths. Follow-on activity includes disabling Windows Defender, deleting shadow copies, neutralizing Windows Update, creating scheduled tasks for persistence, and establishing command-and-control over non-standard ports. Microsoft assesses this activity aligns with publicly reported Silver Fox operations but has not attributed it to a nation-state actor.