VYPR
researchPublished Sep 1, 2026· 1 source

Counterfeit Installers Fuel Deceptive Software Download Campaign

Microsoft Defender Experts are tracking a malware campaign that uses counterfeit software download sites to impersonate trusted vendors and distribute malicious installers, primarily targeting China-based operations.

Microsoft Defender Experts are actively monitoring a sophisticated malware campaign that leverages deceptive software download websites to impersonate legitimate vendors and distribute malicious installers. This campaign targets users seeking to download popular software, leading to compromises across a wide range of industries including healthcare, manufacturing, gaming, technology, logistics, government, and education. The primary focus appears to be on China-based operations of multinational organizations and Chinese-speaking users.

The attack chain begins with users navigating to fraudulent websites that mimic trusted software vendors. These sites present convincing "Download now" buttons, but instead of delivering the legitimate software, they serve malicious installer archives. A key characteristic of this campaign is that the downloaded archive files often maintain the same filename but have varying hashes with each download, indicating that the payload is generated dynamically on the server-side per request. This makes it more challenging for traditional signature-based detection methods to identify the threat.

Microsoft observed that these spoofed download pages are hosted on domains using country-code top-level domains like .com.cn and .hl.cn, embedding the impersonated brand names to enhance their legitimacy. While the impersonated brands are diverse—ranging from Razer and Microsoft Edge to Kaspersky and various utility software—the underlying infrastructure often converges. Multiple seemingly unrelated spoofed domains resolve to the same delivery infrastructure, including dedicated delivery domains and suspected attacker-controlled Alibaba Cloud Object Storage Service (OSS) buckets.

Once executed, the malicious installers deploy malware designed to establish persistence on the compromised system. This malware also attempts to weaken existing security protections, making it harder for security software to detect and remove it. Furthermore, it communicates with attacker-controlled infrastructure, enabling the threat actors to maintain command and control over the infected devices and potentially exfiltrate sensitive data or deploy further malicious payloads.

Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign. However, the campaign has not been definitively attributed to a specific nation-state actor. Microsoft Defender has successfully detected and disrupted activity at various stages of the attack, including automated containment measures.

To mitigate the risks associated with this campaign, organizations should prioritize preventing downloads from untrusted software sources. It is crucial to ensure that security protections such as Microsoft Defender SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled and up-to-date. These measures can help identify, block, and respond to related malicious activity more effectively, safeguarding systems against these deceptive download tactics.

Synthesized by Vypr AI