ZeroHour
Microsoft Security Blogpublished ()ingested Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar1

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

highThreat actor exploited in the wildimportance 63
AI summary · glm-5.3-flash

Microsoft tracks a counterfeit software-installer campaign compromising multinationals' China operations, moderately linked to the Silver Fox (Yinhu) actor.

Microsoft Defender Experts is tracking an active campaign using spoofed software download sites for brands such as Razer, Kaspersky, Microsoft Edge, Calibre, and Baidu Netdisk on .com.cn and .hl.cn domains, delivering installer archives whose hashes change per download, indicating server-side payload generation. The implants establish persistence, weaken security protections, and communicate with attacker-controlled infrastructure, with confirmed compromises across healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft assesses with moderate confidence that the activity matches the publicly reported Silver Fox (Yinhu) fake software campaign; it has not attributed it to a nation-state actor.

  • Look-alike vendor download pages funnel to shared delivery hosts such as gehie246[.]com and rotating domains.
  • Installer archives keep the same filename while hashes change, indicating per-request server-side generation.
  • Victims are predominantly China-based operations of multinationals and Chinese-speaking users.
  • Microsoft recommends SmartScreen, network protection, tamper protection, and Defender XDR.

Indicators of compromiseAll →

TypeIndicatorContext
domainapp-microsoft-edge.com.cnc-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security soft
domainbaidu-pan.com.cns zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn S
domaincalibre-ebook.com.cnpc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonation
domaincc8ttkv35b.comand to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attack
domaincn-drawio.com.cnm Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Perip
domaincom.cnbapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains im
domaingehie246.comnd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named a
domaingw-sogou.com.cning SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book Mi
domainhl.cnl, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unr
domainkaspersky-lab.hl.cnalidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[
domainmindmoster.com.cnibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtool
domainn7b8t85zsg.comhosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Clou
domainocam-pc.com.cnan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming
domainoijfwe.netled Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads Alibab
domainpc-razerzone.com.cnlemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery
domainsejda.hl.cnspersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao
domainsteelseries-cn.com.cnapture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Cali
domaintranslate-youdao.hl.cnPDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk ut
domainwww.gehie246.comns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A de
domainyimxg25tiy.comnation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71
domainzh-diskgenius.com.cnictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn C
sha2561bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17ocessFolderPath C:\ProgramData\.exe InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 InitiatingProcessCommandLine ".exe" InitiatingProcessCreati
sha2566d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8ogram Files (x86)\72q1o6\40gK5T.exe InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 InitiatingProcessCommandLine "40gK5T.exe" InitiatingProcess
urlhttp://www.gehie246[e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[
Full article2,377 words · extracted from microsoft.com · click to collapse

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor. Microsoft Defender detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption. Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.

Attack chain overview

The campaign follows a consistent attack chain from a spoofed vendor download page to a self-protecting, persistent implant. The stages below trace that chain — initial access, delivery, execution, persistence, privilege escalation, defense evasion, and command and control.

Figure 1. Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Campaign scope and targeting

Microsoft observed affected devices predominantly associated with China-based operations and Chinese-speaking users, consistent with the Chinese-language lure content and the .com.cn and .hl.cn infrastructure. Confirmed activity spans medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education across multiple organizations and industries.

Initial access: spoofed software-download sites

The entry point is a fraudulent software-download website that spoofs a legitimate vendor. In one case, endpoint telemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named archive were written within roughly 69 seconds — a direct observation of server-side payload regeneration.

Across the estate, FileOriginReferrerUrl telemetry ties each downloaded archive to the impersonation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Cloud Object Storage Service (OSS) bucket. The lure domains predominantly use .com.cn , .hl.cn , and .cn and embed the impersonated brand name.

Delivery: a dynamically generated installer archive

The following examples illustrate how look-alike domains routed users to the same delivery infrastructure while preserving brand-specific lure pages.

When the user selects the download control, Microsoft Edge retrieves a malicious installer archive from a small set of dedicated delivery domains.

pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader

A defining characteristic is that the archive keeps the same filename while its hash changes on every download — a strong indicator the payload is generated server-side, per request. Microsoft observed families of same-named archives ( app_setup.* , zinst.* , zintall.* , intsoft.* , innstll.* ) whose contents differ across downloads while the delivery URL stays constant; the full validated hash set is in the indicators of compromise below.

kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down

pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down

calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down

Brand-impersonation infrastructure

The campaign runs a large, uniform set of vendor look-alike pages on .com.cn and .hl.cn domains, each cloning the real product’s branding and presenting a prominent “Download now” button. All funnel to the same delivery and payload infrastructure.

Impersonated brand Spoofed domain (defanged) Category

Razer (Synapse driver) pc-razerzone[.]com[.]cn Peripherals / drivers

Microsoft Edge app-microsoft-edge[.]com[.]cn Browser

Kaspersky kaspersky-lab[.]hl[.]cn Security software

Sejda PDF sejda[.]hl[.]cn Productivity

NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation

DiskGenius zh-diskgenius[.]com[.]cn Disk utility

Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage

oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture

draw.io cn-drawio[.]com[.]cn Diagramming

SteelSeries steelseries-cn[.]com[.]cn Peripherals

Sogou gw-sogou[.]com[.]cn Input method

Calibre calibre-ebook[.]com[.]cn E-book

MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping

Others pc-codex, jinshan-cibapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities

Although these domains impersonate unrelated vendors, they are not independently hosted. Infrastructure enrichment, corroborated by Microsoft telemetry where the two overlap, resolves them into two groupings. Six domains resolve within AS132839, spread across four unrelated netblocks and three registered country codes, and share a common pair of nameservers. Two further domains resolve within AS8796 in a single /21, using a different nameserver pair. One additional domain is served through a content delivery network (CDN), concealing its origin. Because hosting and Domain Name System (DNS) are frequently bundled by the same reseller, these are best read as two consistent procurement channels rather than two independent corroborating signals.

The practical implication for defenders is that netblock- and geography-based grouping will miss these relationships, while Autonomous System Number (ASN)-level analysis surfaces them.The autonomous system remains constant even where the address space and registered country vary. These are shared commercial hosting and DNS providers carrying substantial unrelated tenancy, so the ASN and nameserver should be treated as hunting pivots, not blocklist entries.

The following capture shows a representative impersonation page served by the campaign. The pages are high-fidelity clones of a legitimate vendor’s site with a prominent download call-to-action.

Figure 2b. Counterfeit Microsoft Edge download page hosted on the look-alike domain app-microsoft-edge[.]com[.]cn, with a prominent download button.

Execution: a wrapped installer drops a randomized stage-one payload

The wrapper installer creates a randomized executable path while reusing stable payload content, making names unreliable but behavior and hashes useful for detection.

Opening the archive yields a wrapper installer whose name follows a generated pattern (for example, a_instapp83353001.exe or ainst8663586104.exe ).

Executing the wrapper creates and launches a stage-one payload at a randomized path under a world-writable or system location; the directory and file names are randomized, but the payload content is stable. The same stage-one 256-bit Secure Hash Algorithm (SHA-256) (676a2a7b94ca…) was observed under many names and paths.

C:\Users\Public\sE94yD\aLcUaw.exe (SHA-256 676a2a7b94ca… stage-one)

C:\Users\Public\nvdPX5\2b3L5i.exe (SHA-256 676a2a7b94ca… stage-one)

C:\Program Files (x86)\i3LH90\ErNGxW.exe (SHA-256 6d6ba2bc9ad4… later-stage)

C:\Program Files (x86)\Q8Maj\7EIr6VA.exe (SHA-256 6d6ba2bc9ad4… later-stage)

C:\ProgramData\zsMmvukD\beuv4Mie.exe (SHA-256 c6100166e2d3… persistent)

The end-to-end chain is visible as a parent-to-child process tree: msedge.exe writes the archive, an archiving tool ( 7zFM.exe , 360zip.exe , or WinRAR.exe ) extracts it, the bundled wrapper runs, and the wrapper launches the randomized stage-one payload.

msedge.exe downloads app_setup.6653004.zip

└─ 7zFM.exe / 360zip.exe / WinRAR.exe (user opens the downloaded archive)

└─ a_instapp83353001.exe (wrapper installer bundled in the archive)

└─ C:\Users\Public\yZ6A88\9bEELI.exe (stage-one payload, randomized)

Payloads are masqueraded; Microsoft confirmed the masquerade through file metadata on the later-stage payload (SHA-256 6d6ba2bc…), staged at C:\Program Files (x86)\<random>\ . The binary’s version resource declares CompanyName: “Speech Processing Solutions GmbH”, FileDescription: “Philips Speech Driver Client Configuration”, OriginalFileName: PhilipsSpeechDriverConfiguration.exe, and ProductVersion: 4.7.471.07,while executing from a randomized directory under a randomized file name. The same resource retains an unfilled build-template placeholder, ProductName: “TODO: <Product name>”, indicating the version information was fabricated for the payload rather than inherited from genuine vendor software. Microsoft also observed svchost.exe executing from a non-system path ( D:\hellothere\svchost.exe ) rather than C:\Windows\System32 .

FileName XPSPLOG.dll

FolderPath C:\Program Files (x86)\72q1o6\XPSPLOG.dll

InitiatingProcessFileName 40gK5T.exe

InitiatingProcessFolderPath C:\Program Files (x86)\72q1o6\40gK5T.exe

InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8

InitiatingProcessCommandLine "40gK5T.exe"

InitiatingProcessVersionInfoCompanyName Speech Processing Solutions GmbH

InitiatingProcessVersionInfoFileDescription Philips Speech Driver Client Configuration

InitiatingProcessVersionInfoOriginalFileName PhilipsSpeechDriverConfiguration.exe

InitiatingProcessVersionInfoProductVersion 4.7.471.07

InitiatingProcessVersionInfoProductName TODO:

InitiatingProcessParentFileName svchost.exe

A payload staged under C:\ProgramData\<random>\ (SHA-256 c6100166…) carries the version metadata of the Indigo Rose TrueUpdate Client (OriginalFileName: tu_rt.exe, ProductVersion: 3.8.0.0) and exhibits that product’s runtime behavior, writing _ir_tu2_temp_* artifacts to the user’s temp directory on each execution. Dropped by the later-stage payload and launched repeatedly by the Task Scheduler service, it connects to an attacker-controlled Alibaba Cloud OSS bucket over Transport Layer Security (TLS) and writes a further payload to a second randomized C:\ProgramData\ directory — a legitimate update mechanism repurposed for payload delivery.

00:24:43 ErNGxW.exe (6d6ba2bc…) creates C:\ProgramData\zsMmvukD\beuv4Mie.exe (c6100166…)

00:24:43 beuv4Mie.exe executes ← parent: svchost.exe -k netsvcs -p -s Schedule

00:24:44 beuv4Mie.exe → ConnectionSuccess | upitem.oss-cn-hangzhou.aliyuncs.com | 443

00:24:44 beuv4Mie.exe creates C:\ProgramData\uwMUCYBN\SaYC4Mga.exe (f33d160d…)

02:12:22 beuv4Mie.exe creates …\Temp\_ir_tu2_temp_4 ← TrueUpdate runtime artifact

02:44:20 beuv4Mie.exe re-executes (scheduled task) → _ir_tu2_temp_5

02:59:00 … _temp_6 03:15:54 … _temp_7 08:02:52 … _temp_8

08:32:20 … _temp_9 08:38:51 … _temp_11

Wrapper installer Stage-one payload created

a_instapp83353001.exe C:\Users\Public\yZ6A88\9bEELI.exe

z_instapp83351010.exe C:\Users\Public\Y93eny\Ge86Zr.exe

ainstaller-86533003.exe C:\Users\Public\Mmzm0e\Lrrhwp.exe

ainst8663586104.exe C:\Users\Public\YJMvsB\BcQVw7.exe

Alternate execution vector: Windows Installer (msiexec)

In parallel with the wrapped-installer chain, Microsoft observed a second execution vector that uses the Windows Installer service. The installer performs its intended function; what the campaign gains is execution under a signed, trusted Windows component. The extracted installer invokes msiexec.exe in embedded mode, which writes and launches a randomized executable into a world-writable C:\Users\Public\<random>\ directory, the same masquerade pattern as the wrapper chain, but delivered through msiexec.exe .

msiexec.exe -Embedding E Global\MSI0000

└─ C:\Users\Public\\.exe (payload, randomized path/name)

The behavior is consistent and repeated: more than twenty distinct payload names were written this way, spawned by a range of parents including msedge.exe , explorer.exe , and svchost.exe .

Persistence and recurring execution: disguised scheduled tasks

Persistence and recurring execution are achieved through scheduled tasks whose display names imitate routine IT or productivity jobs (for example “Deadline Mission Target” and “Hierarchy Tools Smooth Inventory”), each launching a specific payload staged under C:\ProgramData\ .

Each task launches a specific payload:

Scheduled task name Payload launched

\Deadline Mission Target 7fYptijy.exe

\Hierarchy Tools Smooth Inventory beuv4Mie.exe

\Empowering Status Tools productivity Ahead SaYC4Mga.exe

\5nboF aLcUaw.exe (stage-one)

The persistent payloads are staged in locations such as C:\ProgramData\7fYptijy.exe , C:\ProgramData\zsMmvukD\beuv4Mie.exe , and C:\ProgramData\uwMUCYBN\SaYC4Mga.exe . Because the payloads are launched by the Task Scheduler service (parented to svchost.exe -k netsvcs -p -s Schedule ) and multiple staggered tasks run per device, affected hosts exhibit a characteristic ~60-second re-execution cadence.

Privilege escalation: SYSTEM scheduled task and process injection

To perform privileged actions such as writing Microsoft Defender exclusions, the malware creates a short-lived scheduled task that runs as SYSTEM ( SCHTASKS /Create … /RL HIGHEST /RU “SYSTEM” ), executes the privileged action, then immediately runs and deletes the task

SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM"

/TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\"

/v \"C:\Program Files (x86)\NPq6k16Om\" /t REG_DWORD /d 0 /f"

SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F

The /RL HIGHEST /RU “SYSTEM” combination elevates the exclusion write to SYSTEM, and the create-run-delete sequence minimizes the footprint of the helper task. Process injection was also observed. A persistent campaign payload (SHA-256 1bd3662d…), launched from C:\ProgramData\ by the Task Scheduler service, created a remote thread in a legitimate user application moments after that application started — executing payload code inside the context of a trusted process. Microsoft Defender detected the activity as A process was injected with potentially malicious code .

ActionType CreateRemoteThreadApiCall

InitiatingProcessFileName .exe

InitiatingProcessFolderPath C:\ProgramData\.exe

InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17

InitiatingProcessCommandLine ".exe"

InitiatingProcessCreationTime 2026-07-13 02:44:20.887

InitiatingProcessParentFileName svchost.exe

FileName .exe (target process)

ProcessCommandLine ".exe" -autorun

ProcessCreationTime 2026-07-13 02:44:37.568

AdditionalFields {"IntegrityLevel":8192}

The sequence below shows a single execution cycle end to end: the Task Scheduler service launches the payload, the payload immediately attempts command-and-control on two non-standard ports — both blocked at the host firewall — and, seventeen seconds later, injects into a user application within milliseconds of that application starting.

02:44:20.887 PROC .exe started parent: svchost.exe (Task Scheduler)

02:44:21.971 NETWORK outbound to 47.239.232[.]245:8050 → FirewallOutboundConnectionBlocked

02:44:24.860 NETWORK outbound to 47.243.218[.]255:28300 → FirewallOutboundConnectionBlocked

02:44:37.568 PROC target application starts (-autorun)

02:44:37.604 INJECT CreateRemoteThreadApiCall .exe → target application

Defense evasion: disabling host protections

Follow-on payloads take a layered approach to weakening the host. They add sweeping Microsoft Defender path exclusions via PowerShell ( Add-MpPreference -ExclusionPath ) and the SYSTEM scheduled-task registry write;

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/