Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Silver Fox-linked hackers are using counterfeit software installers to break into Windows systems and weaken the protections meant to stop them.

The campaign relies on convincing download pages that copy well-known software brands and offer a seemingly legitimate file. The operation has affected healthcare, manufacturing, gaming, technology, logistics, government, and education organizations.

Most observed victims were linked to China-based operations or Chinese-speaking users, but the lure can cross industry boundaries.

Microsoft analysts identified the activity as consistent, with moderate confidence, with the publicly reported Silver Fox, also known as Yinhu, fake-software campaign.

It has not attributed the activity to a nation-state actor, but said the malware establishes a foothold, lowers defenses, and contacts attacker-controlled servers.

Campaign attack chain (Source – Microsoft)

Microsoft said in a report shared with Cyber Security News (CSN). The report underlines a simple risk: a routine-looking download from a cloned vendor page can become a full endpoint compromise.

Silver Fox-Linked Hackers Use Fake Software Installers

The attack begins on look-alike websites that imitate vendors such as Razer, Microsoft Edge, Kaspersky, Sejda PDF, and other popular tools.

After a visitor selects Download now, the site supplies a ZIP archive whose filename remains unchanged while its contents and hash change with every request.

That per-download rebuilding makes simple file-name blocking less reliable. In one observed case, two different copies of the same archive appeared within about 69 seconds.

The pattern resembles other fake installer malware campaigns, where familiar branding makes a dangerous first click feel ordinary.

Opening the archive launches a wrapper that places an executable in a randomly named directory, including locations under UsersPublic, ProgramData, or Program Files (x86).

A second path uses Windows Installer, or msiexec.exe, so malicious code runs through a trusted Windows component while the user believes an installation is proceeding.

Counterfeit Microsoft Edge download page (Source - Microsoft)
Counterfeit Microsoft Edge download page (Source – Microsoft)

The payloads then create scheduled tasks with harmless-sounding names, including Deadline Mission Target and Hierarchy Tools Smooth Inventory.

This restarts code about every 60 seconds, showing why Windows scheduled task abuse remains a useful persistence technique for intruders.

More seriously, the malware creates a short-lived task running as SYSTEM, Windows’ highest local privilege, to add broad Microsoft Defender exclusions.

It also uses PowerShell to exclude folders, writes a malicious code-integrity policy, and may inject code into another program, reducing the chance that security tools inspect the files involved.

Recovery and detection priorities

The campaign does not stop at avoiding antivirus checks. Researchers observed commands that delete volume shadow copies, making recovery harder, and actions that stop or disable Windows Update services.

The attackers also harden their directories against removal and communicate with control servers over unusual ports before further activity.

Microsoft reported automated containment alongside hands-on-keyboard activity and attempted SMB movement.

A device may be contained, yet scheduled tasks and other persistence still need full removal by an incident responder.

Organizations should restrict downloads to verified vendor sources and treat brand look-alike pages, especially unexpected ZIP installers, as suspicious.

Attacker activity stages (Source - Microsoft)
Attacker activity stages (Source – Microsoft)

Web and email controls should block the identified delivery routes, while teams should review download referrers, new executables in writable folders, unusual msiexec activity, and recently created scheduled tasks.

Administrators should keep tamper protection and network protection enabled, then alert on Defender exclusion changes, shadow-copy deletion, and attempts to disable update services.

The lesson echoes fake Claude application attacks, in which a deceptive application also tried to reduce Defender visibility before expanding access. Behavior is more durable than a filename because archive names, paths, and some hashes rotate.

Security teams can hunt for the stable file hashes and network indicators below, but should prioritize the sequence of a spoofed-page download, randomly staged executable, SYSTEM task creation, defense tampering, and recurring execution.

For end users, leave a questionable installer unopened, obtain the program from its official publisher, and report the page to IT or security staff.

For defenders, prompt isolation and a review of affected accounts, tasks, exclusions, and network connections can prevent a fake download from becoming a deeper breach.

Indicators of Compromise (IoCs):-

Type Indicator Description
Lure domain pc-razerzone[.]com[.]cn Spoofed Razer download site
Lure domain app-microsoft-edge[.]com[.]cn Spoofed Microsoft Edge download site
Lure domain kaspersky-lab[.]hl[.]cn Spoofed Kaspersky download site
Lure domain sejda[.]hl[.]cn Spoofed Sejda PDF download site
Lure domain translate-youdao[.]hl[.]cn Spoofed NetEase Youdao download site
Lure domain zh-diskgenius[.]com[.]cn Spoofed DiskGenius download site
Lure domain baidu-pan[.]com[.]cn Spoofed Baidu Netdisk download site
Lure domain ocam-pc[.]com[.]cn Spoofed oCam Screen Recorder download site
Lure domain cn-drawio[.]com[.]cn Spoofed draw.io download site
Lure domain steelseries-cn[.]com[.]cn Spoofed SteelSeries download site
Lure domain gw-sogou[.]com[.]cn Spoofed Sogou download site
Lure domain calibre-ebook[.]com[.]cn Spoofed Calibre download site
Lure domain mindmoster[.]com[.]cn MindMaster typosquatting domain
Delivery URL hxxps://www[.]gehie246[.]com/712down Malicious installer delivery endpoint
Delivery URL hxxps://yimxg25tiy[.]com/73inst Rotating malicious installer delivery endpoint
Delivery URL hxxps://cc8ttkv35b[.]com/7qinst Rotating malicious installer delivery endpoint
Delivery URL hxxps://n7b8t85zsg[.]com/ins711 Rotating malicious installer delivery endpoint
Cloud staging URL hxxps://newopt001[.]oss-cn-hongkong[.]aliyuncs[.]com/innstll.1.0.61.zip Attacker-controlled cloud-hosted ZIP payload
Cloud staging domain upitem[.]oss-cn-hangzhou[.]aliyuncs[.]com Observed cloud object-storage staging host
C2 domain iualef[.]net Command-and-control domain
C2 domain oijfwe[.]net Command-and-control domain
C2 domain euioxu[.]net Command-and-control domain
C2 domain czijbh[.]net Command-and-control domain
C2 domain wfmwsj[.]net Command-and-control domain
C2 domain tbdqxq[.]net Command-and-control domain
C2 endpoint 202.95.14[.]237:5090 Primary observed command-and-control endpoint
C2 endpoint 103.183.3[.]162:5090 Observed command-and-control endpoint
C2 endpoint 103.156.25[.]35:7031 Observed command-and-control endpoint
C2 endpoint 47.239.232[.]245:8050 Observed command-and-control endpoint
C2 endpoint 47.243.218[.]255:28300 Observed command-and-control endpoint
C2 IP address 161.248.87[.]157 Command-and-control IP listed in hunting guidance
SHA-256 676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7 Stable stage-one payload
SHA-256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 Later-stage payload
SHA-256 c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdf Networking payload
SHA-256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 Persistent payload associated with process injection
SHA-256 c6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73faf TrueUpdate-based persistent loader
SHA-256 f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81b Persistent and networking payload
SHA-256 e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3 Supporting malicious DLL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems appeared first on Cyber Security News.