SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Microsoft ties Silver Fox fake download sites to Windows malware mainly hitting Chinese-speaking users.
Microsoft assesses with moderate confidence that counterfeit software download sites serving malicious Windows installers are consistent with Silver Fox, also called Yinhu, and does not attribute the activity to a nation-state. Observed compromises span several industries and mainly affect Chinese-speaking users; archives can change between requests while later stages create scheduled tasks, alter exclusions, disable Windows Update, remove recovery copies, and contact attacker infrastructure. Separately, Pelagos Intel examined a finance-themed WhatsApp attachment sent to a Malaysian recipient that paired a signed Guangzhou Kugou launcher with an unsigned DLL, set a Run-key startup entry, and made repeated connections to 134.122.155.135:443. The two chains are not shown to share infrastructure.
- Fake sites imitate browsers, security tools, and utilities.
- ZIP payloads can be rebuilt per request, weakening hash detection.
- Later stages add scheduled tasks and alter security settings.
- A separate WhatsApp chain used a signed executable and unsigned DLL.
- Microsoft did not attribute the campaign to a nation-state.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 134.122.155.135 | E558142B844E871084F Unsigned companion DLL Network endpoint 134.122.155.135:443 Repeated outbound connection attempts File name PDF_C28 |
| sha1 | 757bdd02cba91ca59c46e2098a5479c1abc1fdbe | Signer identified for the executable Certificate thumbprint 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE Certificate identifier PDB path D:\buildbot\build1\desktop_ |
| sha256 | 9f2caeda208c9d729b44f31c32b5e1eeef18d84d6e36b04afe15d894d3809672 | s of Compromise (IoCs):- Type Indicator Description SHA-256 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 Delivered ZIP archive SHA-256 E2BF8B7CD396EE950A5B6911EA098 |
| sha256 | c1e184615241fe69db3bf4093a22c7c0bf5d6072d2f51e558142b844e871084f | EB0F43364E9686CDA78B1243C62E4830D Signed executable SHA-256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F Unsigned companion DLL Network endpoint 134.122.155.135:443 |
| sha256 | e2bf8b7cd396ee950a5b6911ea098c2e49d4ed002a6c04d5d660ccd4f7d66baa | 8D84D6E36B04AFE15D894D3809672 Delivered ZIP archive SHA-256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA IMG disk image SHA-256 F712C2A8B4ABF2E299A2B480020333DEB0F4 |
Full article899 words · extracted from cybersecuritynews.com · click to collapse
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access.
Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users.
The attackers rely on a simple habit: people search for an application, recognize its branding, and click download. Other Silver Fox-related activity has used messages and attachments.
Researchers at Pelagos Intel identified one such separate chain involving a finance-themed WhatsApp message aimed at a Malaysian recipient.
The attachment carried a signed program and an unsigned library. That finding does not establish that the WhatsApp operation used the counterfeit websites.
Microsoft assesses the fake-installer campaign as consistent with Silver Fox, also called Yinhu, with moderate confidence. It has not attributed the operation to a nation-state actor.
Pelagos Intel said in a report shared with Cyber Security News (CSN) that its separately analyzed files established persistence and repeatedly attempted to reach an external server.
SilverFox Hackers Built Fake Software Sites
The cloned pages copy the look of legitimate software download sites, including pages for browsers, security tools, and everyday utilities.
Microsoft traced visitors from a counterfeit page to a download host serving a ZIP archive. Its Silver Fox fake installer investigation describes how familiar branding can hide a dangerous installation chain.
.webp)
Two archives with the same name arrived roughly 69 seconds apart, yet contained different material. Microsoft says the archive can be rebuilt for each request while its name and download address stay the same.
That makes a single archive hash a poor way to recognize every copy, but it is not evidence that the websites identify and selectively deceive security researchers.
Once opened, the archive launches a wrapper that places malicious code in a randomly named Windows folder. Another observed route runs through Windows Installer, a system component.
A user expecting a routine installation may therefore miss the extra program starting in the background, especially when the visible download page looks convincing.
This approach has precedent: a fake security software download was previously linked to a Silver Fox-related infection. These were separate operations.
They do, however, show why recognizable branding and apparently ordinary installers deserve closer scrutiny when the download source cannot be verified.
Persistence And Detection Clues
Microsoft found that later stages created scheduled tasks to restart malicious programs and briefly ran a task with high system privileges to change security exclusions.
The malware also tried to disable Windows Update, remove recovery copies, and contact attacker-controlled infrastructure. Such changes can make both discovery and cleanup harder after the original installer has closed.
.webp)
Pelagos Intel’s WhatsApp case followed a different technical route. A validly signed launcher called functions in an unsigned library that presented itself as a Windows desktop component.
The library decoded data and copied transformed content into executable memory. The same files were then copied into a user profile, with a startup registry entry set to run them again.
During testing, Pelagos recorded 96 connection attempts about three seconds apart. It also observed a successful decryption operation whose length matched a transformation identified during code analysis.
These observations support a configured, persistent loader, but the report does not demonstrate that this chain and Microsoft’s fake-site campaign are the same intrusion.
Earlier reporting on trusted software loading malware illustrates why a valid signature on one file cannot clear every neighboring component.
Likewise, tax themed Silver Fox lures show that an apparently credible document or message can be the first step toward a separate infection. These links provide context, not proof of shared infrastructure. This distinction matters when teams compare samples and reports.
For the counterfeit-site campaign, Microsoft recommends downloading from verified sources, watching for unexpected archive downloads, and alerting on suspicious scheduled tasks or security-setting changes.
For the WhatsApp chain, Pelagos highlights the unusual startup entry, staged file pair, and regular outbound attempts as useful investigation leads. Teams should verify which chain they are investigating before applying the indicators below.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 | Delivered ZIP archive |
| SHA-256 | E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA | IMG disk image |
| SHA-256 | F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D | Signed executable |
| SHA-256 | C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F | Unsigned companion DLL |
| Network endpoint | 134.122.155.135:443 | Repeated outbound connection attempts |
| File name | PDF_C2841_20260911100446.zip | WhatsApp attachment |
| File name | PDF_C2089_20260911100446.exe | Signed executable |
| File name | active_desktop_render_x64.dll | Companion DLL |
| Staging path | %APPDATA%\Microsoft\Update\ | Directory used to stage both files |
| Registry key | HKCU\Software\Microsoft\Windows\CurrentVersion\Run | Startup persistence location |
| Registry value | MicrosoftUpdate | Observed startup value name |
| Signer | Guangzhou Kugou Technology Co., Ltd. | Signer identified for the executable |
| Certificate thumbprint | 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE | Certificate identifier |
| PDB path | D:\buildbot\build1\desktop_screen\build\bin\active_desktop_launcher_x64.pdb | Build-path artifact |
| Configuration marker | @@RAPID_CFG_START@@ | Marker found in decrypted data |
| File metadata | active_desktop_launcher.exe | Executable identity in version resources |
| File metadata | dwmapi.dll | Original filename claimed in DLL metadata |
| Hunting string | ReleaseFromExplorer | Static-analysis clustering term |
| Hunting string | _ipcfr_wqkqzk | Static-analysis clustering term |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.