SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access.

Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users.

The attackers rely on a simple habit: people search for an application, recognize its branding, and click download. Other Silver Fox-related activity has used messages and attachments.

Researchers at Pelagos Intel identified one such separate chain involving a finance-themed WhatsApp message aimed at a Malaysian recipient.

The attachment carried a signed program and an unsigned library. That finding does not establish that the WhatsApp operation used the counterfeit websites.

Microsoft assesses the fake-installer campaign as consistent with Silver Fox, also called Yinhu, with moderate confidence. It has not attributed the operation to a nation-state actor.

Pelagos Intel said in a report shared with Cyber Security News (CSN) that its separately analyzed files established persistence and repeatedly attempted to reach an external server.

SilverFox Hackers Built Fake Software Sites

The cloned pages copy the look of legitimate software download sites, including pages for browsers, security tools, and everyday utilities.

Microsoft traced visitors from a counterfeit page to a download host serving a ZIP archive. Its Silver Fox fake installer investigation describes how familiar branding can hide a dangerous installation chain.

Infection Chain (Source - Pelagos Intel)
Infection Chain (Source – Pelagos Intel)

Two archives with the same name arrived roughly 69 seconds apart, yet contained different material. Microsoft says the archive can be rebuilt for each request while its name and download address stay the same.

That makes a single archive hash a poor way to recognize every copy, but it is not evidence that the websites identify and selectively deceive security researchers.

Once opened, the archive launches a wrapper that places malicious code in a randomly named Windows folder. Another observed route runs through Windows Installer, a system component.

A user expecting a routine installation may therefore miss the extra program starting in the background, especially when the visible download page looks convincing.

This approach has precedent: a fake security software download was previously linked to a Silver Fox-related infection. These were separate operations.

They do, however, show why recognizable branding and apparently ordinary installers deserve closer scrutiny when the download source cannot be verified.

Persistence And Detection Clues

Microsoft found that later stages created scheduled tasks to restart malicious programs and briefly ran a task with high system privileges to change security exclusions.

The malware also tried to disable Windows Update, remove recovery copies, and contact attacker-controlled infrastructure. Such changes can make both discovery and cleanup harder after the original installer has closed.

Valid Authenticode signature (Source - Pelagos Intel)
Valid Authenticode signature (Source – Pelagos Intel)

Pelagos Intel’s WhatsApp case followed a different technical route. A validly signed launcher called functions in an unsigned library that presented itself as a Windows desktop component.

The library decoded data and copied transformed content into executable memory. The same files were then copied into a user profile, with a startup registry entry set to run them again.

During testing, Pelagos recorded 96 connection attempts about three seconds apart. It also observed a successful decryption operation whose length matched a transformation identified during code analysis.

These observations support a configured, persistent loader, but the report does not demonstrate that this chain and Microsoft’s fake-site campaign are the same intrusion.

Earlier reporting on trusted software loading malware illustrates why a valid signature on one file cannot clear every neighboring component.

Likewise, tax themed Silver Fox lures show that an apparently credible document or message can be the first step toward a separate infection. These links provide context, not proof of shared infrastructure. This distinction matters when teams compare samples and reports.

For the counterfeit-site campaign, Microsoft recommends downloading from verified sources, watching for unexpected archive downloads, and alerting on suspicious scheduled tasks or security-setting changes.

For the WhatsApp chain, Pelagos highlights the unusual startup entry, staged file pair, and regular outbound attempts as useful investigation leads. Teams should verify which chain they are investigating before applying the indicators below.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 Delivered ZIP archive
SHA-256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA IMG disk image
SHA-256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D Signed executable
SHA-256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F Unsigned companion DLL
Network endpoint 134.122.155.135:443 Repeated outbound connection attempts
File name PDF_C2841_20260911100446.zip WhatsApp attachment
File name PDF_C2089_20260911100446.exe Signed executable
File name active_desktop_render_x64.dll Companion DLL
Staging path %APPDATA%MicrosoftUpdate Directory used to stage both files
Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun Startup persistence location
Registry value MicrosoftUpdate Observed startup value name
Signer Guangzhou Kugou Technology Co., Ltd. Signer identified for the executable
Certificate thumbprint 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE Certificate identifier
PDB path D:buildbotbuild1desktop_screenbuildbinactive_desktop_launcher_x64.pdb Build-path artifact
Configuration marker @@RAPID_CFG_START@@ Marker found in decrypted data
File metadata active_desktop_launcher.exe Executable identity in version resources
File metadata dwmapi.dll Original filename claimed in DLL metadata
Hunting string ReleaseFromExplorer Static-analysis clustering term
Hunting string _ipcfr_wqkqzk Static-analysis clustering term

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News.