ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

highMalware exploited in the wildimportance 68
AI summary · glm-5.3-flash

Fake software-download sites distribute installers that disable Windows Update and weaken Defender, attributed to China-linked cluster Silver Fox.

Microsoft says an active campaign uses counterfeit vendor websites on .com.cn and .hl.cn infrastructure with Chinese-language lures to deliver server-side generated installers that establish scheduled-task persistence, add Defender exclusions, delete shadow copies, and stop services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations of multinationals and Chinese-speaking users. Microsoft assesses with moderate confidence the activity matches the Silver Fox (Yinhu) cluster, historically tied to Gh0st RAT and ValleyRAT, with C2 over non-standard ports like 5090 and 7088-7090 via domains iualef[.]net and oijfwe[.]net. Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT.

  • Payload hash changes on every download, indicating per-request server-side generation
  • Malware disables Windows Update, deletes volume shadow copies and locks payload directories via DACLs
  • Second execution vector abuses msiexec.exe to launch randomized executables
  • Silver Fox motivated by both cyber espionage and financial gain per Kaspersky
  • Expel links ValleyRAT use to GoldenEyeDog sub-group CuboidalCanine targeting gambling

Indicators of compromiseAll →

TypeIndicatorContext
domainapp-microsoft-edge.com.cn.]com." Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio
domainbaidu-pan.com.cnt websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[
domaincalibre-ebook.com.cnbelow - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[
domaincn-drawio.com.cnge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[
domaingehie246.comlure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below - app
domaingw-sogou.com.cnan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.
domainiualef.netand 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of th
domainkaspersky-lab.hl.cne-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.
domainmindmoster.com.cnawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.
domainocam-pc.com.cnou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[
domainoijfwe.netomains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of the campaign is, as M
domainpc-razerzone.com.cnrsky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-you
domainsejda.hl.cnoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh
domainsteelseries-cn.com.cnocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The
domaintranslate-youdao.hl.cnerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelit
domainzh-diskgenius.com.cnl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimat
Full article828 words · extracted from thehackernews.com · click to collapse

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft said .

The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.

The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (aka WinOS 4.0).

The websites observed as part of the campaign are hosted on the .com.cn and .hl.cn infrastructure and use Chinese-language lure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below -

app-microsoft-edge[.]com[.]cn

baidu-pan[.]com[.]cn

calibre-ebook[.]com[.]cn

cn-drawio[.]com[.]cn

gw-sogou[.]com[.]cn

kaspersky-lab[.]hl[.]cn

mindmoster[.]com[.]cn

ocam-pc[.]com[.]cn

pc-razerzone[.]com[.]cn

sejda[.]hl[.]cn

steelseries-cn[.]com[.]cn

translate-youdao[.]hl[.]cn

zh-diskgenius[.]com[.]cn

The web pages are high-fidelity clones of the legitimate vendor's site and feature a prominent download call-to-action. Tellingly, the archive downloaded from the site maintains the same file name while its hash changes on every download, indicating that the payload is generated server-side on the fly for every request.

Opening the archive leads to a wrapper installer (e.g., "a_instapp83353001.exe" or "ainst8663586104.exe"), which, upon execution, launches the first stage payload. Separately, Microsoft said it observed a second execution vector that makes use of the trusted Windows Installer service ("msiexec.exe") to launch a randomized executable, mirroring the same masquerade pattern as the wrapper chain.

Regardless of the method used, persistence is achieved through scheduled tasks that imitate routine IT or productivity jobs. The malware is also responsible for creating a short-lived scheduled task that runs as SYSTEM and configures Microsoft Defender exclusions via PowerShell, deletes volume shadow copies, and ensures payload directories cannot be removed by standard users by modifying their discretionary access control lists (DACLs) using icacls .

In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update dynamic-link libraries (DLLs), and deleting the SoftwareDistribution cache.

Once all these steps are carried out, the malware establishes command-and-control (C2) over application-layer protocols on non-standard ports like 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net."

It's unclear what the end goal of the campaign is, as Microsoft said Defender detected and initiated automated containment procedures through attack disruption to limit the attack's impact further.

The disclosure comes merely days after Kaspersky detailed a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, while using it to initiate a DLL sideloading chain responsible for delivering ValleyRAT.

"The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user," Kaspersky said . "In this case, however, the attackers use it to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL."

The backdoor, besides taking steps to protect its process and prevent it from being terminated, captures keystrokes and clipboard contents, and saves the contents to a file on disk. It also periodically scans for active windows belonging to applications that could be used to analyze processes or traffic.

ValleyRAT is a sophisticated implant with a wide range of features that allows it to collect system information, reboot/shut down the computer, take screenshots, wipe logs, update C2 addresses, download additional DLL or shellcode modules, and send keylogger logs along with clipboard data.

"The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection," Kaspersky said. "Motivated by both cyber espionage and financial gain, Silver Fox targets organizations across multiple countries."

According to a report published by Expel last month, the use of ValleyRAT has also been attributed to a sub-group within GoldenEyeDog known as CuboidalCanine, which is assessed to have moved away from Gh0st RAT "at some point." CuboidalCanine, per the cybersecurity company, targets the gambling industry and uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls.

"This malware isn't unique to any actor, but has been known to be used by GoldenEyeDog ," security researcher Aaron Walton said. "Due to the source code being public, attribution of this malware to any actor relies on factors other than the malware family itself."

In June 2026, Chinese authorities took action against a series of cybercrime cases distributing a new variant of the Silver Fox trojan, state media outlet China Daily reported.

Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/fake-software-installers-disable.html