Silver Fox-linked hackers are using counterfeit software installers to break into Windows systems and weaken the protections meant to stop them.
The campaign relies on convincing download pages that copy well-known software brands and offer a seemingly legitimate file. The operation has affected healthcare, manufacturing, gaming, technology, logistics, government, and education organizations.
Most observed victims were linked to China-based operations or Chinese-speaking users, but the lure can cross industry boundaries.
Microsoft analysts identified the activity as consistent, with moderate confidence, with the publicly reported Silver Fox, also known as Yinhu, fake-software campaign.
It has not attributed the activity to a nation-state actor, but said the malware establishes a foothold, lowers defenses, and contacts attacker-controlled servers.

Microsoft said in a report shared with Cyber Security News (CSN). The report underlines a simple risk: a routine-looking download from a cloned vendor page can become a full endpoint compromise.
Silver Fox-Linked Hackers Use Fake Software Installers
The attack begins on look-alike websites that imitate vendors such as Razer, Microsoft Edge, Kaspersky, Sejda PDF, and other popular tools.
After a visitor selects Download now, the site supplies a ZIP archive whose filename remains unchanged while its contents and hash change with every request.
That per-download rebuilding makes simple file-name blocking less reliable. In one observed case, two different copies of the same archive appeared within about 69 seconds.
The pattern resembles other fake installer malware campaigns, where familiar branding makes a dangerous first click feel ordinary.
Opening the archive launches a wrapper that places an executable in a randomly named directory, including locations under UsersPublic, ProgramData, or Program Files (x86).
A second path uses Windows Installer, or msiexec.exe, so malicious code runs through a trusted Windows component while the user believes an installation is proceeding.

The payloads then create scheduled tasks with harmless-sounding names, including Deadline Mission Target and Hierarchy Tools Smooth Inventory.
This restarts code about every 60 seconds, showing why Windows scheduled task abuse remains a useful persistence technique for intruders.
More seriously, the malware creates a short-lived task running as SYSTEM, Windows’ highest local privilege, to add broad Microsoft Defender exclusions.
It also uses PowerShell to exclude folders, writes a malicious code-integrity policy, and may inject code into another program, reducing the chance that security tools inspect the files involved.
Recovery and detection priorities
The campaign does not stop at avoiding antivirus checks. Researchers observed commands that delete volume shadow copies, making recovery harder, and actions that stop or disable Windows Update services.
The attackers also harden their directories against removal and communicate with control servers over unusual ports before further activity.
Microsoft reported automated containment alongside hands-on-keyboard activity and attempted SMB movement.
A device may be contained, yet scheduled tasks and other persistence still need full removal by an incident responder.
Organizations should restrict downloads to verified vendor sources and treat brand look-alike pages, especially unexpected ZIP installers, as suspicious.

Web and email controls should block the identified delivery routes, while teams should review download referrers, new executables in writable folders, unusual msiexec activity, and recently created scheduled tasks.
Administrators should keep tamper protection and network protection enabled, then alert on Defender exclusion changes, shadow-copy deletion, and attempts to disable update services.
The lesson echoes fake Claude application attacks, in which a deceptive application also tried to reduce Defender visibility before expanding access. Behavior is more durable than a filename because archive names, paths, and some hashes rotate.
Security teams can hunt for the stable file hashes and network indicators below, but should prioritize the sequence of a spoofed-page download, randomly staged executable, SYSTEM task creation, defense tampering, and recurring execution.
For end users, leave a questionable installer unopened, obtain the program from its official publisher, and report the page to IT or security staff.
For defenders, prompt isolation and a review of affected accounts, tasks, exclusions, and network connections can prevent a fake download from becoming a deeper breach.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Lure domain | pc-razerzone[.]com[.]cn |
Spoofed Razer download site |
| Lure domain | app-microsoft-edge[.]com[.]cn |
Spoofed Microsoft Edge download site |
| Lure domain | kaspersky-lab[.]hl[.]cn |
Spoofed Kaspersky download site |
| Lure domain | sejda[.]hl[.]cn |
Spoofed Sejda PDF download site |
| Lure domain | translate-youdao[.]hl[.]cn |
Spoofed NetEase Youdao download site |
| Lure domain | zh-diskgenius[.]com[.]cn |
Spoofed DiskGenius download site |
| Lure domain | baidu-pan[.]com[.]cn |
Spoofed Baidu Netdisk download site |
| Lure domain | ocam-pc[.]com[.]cn |
Spoofed oCam Screen Recorder download site |
| Lure domain | cn-drawio[.]com[.]cn |
Spoofed draw.io download site |
| Lure domain | steelseries-cn[.]com[.]cn |
Spoofed SteelSeries download site |
| Lure domain | gw-sogou[.]com[.]cn |
Spoofed Sogou download site |
| Lure domain | calibre-ebook[.]com[.]cn |
Spoofed Calibre download site |
| Lure domain | mindmoster[.]com[.]cn |
MindMaster typosquatting domain |
| Delivery URL | hxxps://www[.]gehie246[.]com/712down |
Malicious installer delivery endpoint |
| Delivery URL | hxxps://yimxg25tiy[.]com/73inst |
Rotating malicious installer delivery endpoint |
| Delivery URL | hxxps://cc8ttkv35b[.]com/7qinst |
Rotating malicious installer delivery endpoint |
| Delivery URL | hxxps://n7b8t85zsg[.]com/ins711 |
Rotating malicious installer delivery endpoint |
| Cloud staging URL | hxxps://newopt001[.]oss-cn-hongkong[.]aliyuncs[.]com/innstll.1.0.61.zip |
Attacker-controlled cloud-hosted ZIP payload |
| Cloud staging domain | upitem[.]oss-cn-hangzhou[.]aliyuncs[.]com |
Observed cloud object-storage staging host |
| C2 domain | iualef[.]net |
Command-and-control domain |
| C2 domain | oijfwe[.]net |
Command-and-control domain |
| C2 domain | euioxu[.]net |
Command-and-control domain |
| C2 domain | czijbh[.]net |
Command-and-control domain |
| C2 domain | wfmwsj[.]net |
Command-and-control domain |
| C2 domain | tbdqxq[.]net |
Command-and-control domain |
| C2 endpoint | 202.95.14[.]237:5090 |
Primary observed command-and-control endpoint |
| C2 endpoint | 103.183.3[.]162:5090 |
Observed command-and-control endpoint |
| C2 endpoint | 103.156.25[.]35:7031 |
Observed command-and-control endpoint |
| C2 endpoint | 47.239.232[.]245:8050 |
Observed command-and-control endpoint |
| C2 endpoint | 47.243.218[.]255:28300 |
Observed command-and-control endpoint |
| C2 IP address | 161.248.87[.]157 |
Command-and-control IP listed in hunting guidance |
| SHA-256 | 676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7 |
Stable stage-one payload |
| SHA-256 | 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 |
Later-stage payload |
| SHA-256 | c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdf |
Networking payload |
| SHA-256 | 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 |
Persistent payload associated with process injection |
| SHA-256 | c6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73faf |
TrueUpdate-based persistent loader |
| SHA-256 | f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81b |
Persistent and networking payload |
| SHA-256 | e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3 |
Supporting malicious DLL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems appeared first on Cyber Security News.
