Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft tracks a counterfeit software-installer campaign compromising multinationals' China operations, moderately linked to the Silver Fox (Yinhu) actor.
Microsoft Defender Experts is tracking an active campaign using spoofed software download sites for brands such as Razer, Kaspersky, Microsoft Edge, Calibre, and Baidu Netdisk on .com.cn and .hl.cn domains, delivering installer archives whose hashes change per download, indicating server-side payload generation. The implants establish persistence, weaken security protections, and communicate with attacker-controlled infrastructure, with confirmed compromises across healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft assesses with moderate confidence that the activity matches the publicly reported Silver Fox (Yinhu) fake software campaign; it has not attributed it to a nation-state actor.
- Look-alike vendor download pages funnel to shared delivery hosts such as gehie246[.]com and rotating domains.
- Installer archives keep the same filename while hashes change, indicating per-request server-side generation.
- Victims are predominantly China-based operations of multinationals and Chinese-speaking users.
- Microsoft recommends SmartScreen, network protection, tamper protection, and Defender XDR.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | app-microsoft-edge.com.cn | c-razerzone[.]com[.]cn Peripherals / drivers Microsoft Edge app-microsoft-edge[.]com[.]cn Browser Kaspersky kaspersky-lab[.]hl[.]cn Security soft |
| domain | baidu-pan.com.cn | s zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn S |
| domain | calibre-ebook.com.cn | pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down Brand-impersonation |
| domain | cc8ttkv35b.com | and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attack |
| domain | cn-drawio.com.cn | m Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Perip |
| domain | com.cn | bapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains im |
| domain | gehie246.com | nd downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named a |
| domain | gw-sogou.com.cn | ing SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Calibre calibre-ebook[.]com[.]cn E-book Mi |
| domain | hl.cn | l, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities Although these domains impersonate unr |
| domain | kaspersky-lab.hl.cn | alidated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[ |
| domain | mindmoster.com.cn | ibre calibre-ebook[.]com[.]cn E-book MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping Others pc-codex, jinshan-cibapc, zh-tbtool |
| domain | n7b8t85zsg.com | hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Clou |
| domain | ocam-pc.com.cn | an) baidu-pan[.]com[.]cn Cloud storage oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture draw.io cn-drawio[.]com[.]cn Diagramming |
| domain | oijfwe.net | led Multiple C:\ProgramData\ payloads 103.183.3[.]162:5090 (oijfwe[.]net) Connection failed Stage-one / persistent payloads Alibab |
| domain | pc-razerzone.com.cn | lemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery |
| domain | sejda.hl.cn | spersky kaspersky-lab[.]hl[.]cn Security software Sejda PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao |
| domain | steelseries-cn.com.cn | apture draw.io cn-drawio[.]com[.]cn Diagramming SteelSeries steelseries-cn[.]com[.]cn Peripherals Sogou gw-sogou[.]com[.]cn Input method Cali |
| domain | translate-youdao.hl.cn | PDF sejda[.]hl[.]cn Productivity NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk ut |
| domain | www.gehie246.com | ns. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader A de |
| domain | yimxg25tiy.com | nation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins71 |
| domain | zh-diskgenius.com.cn | ictionary translate-youdao[.]hl[.]cn Translation DiskGenius zh-diskgenius[.]com[.]cn Disk utility Baidu Netdisk (Pan) baidu-pan[.]com[.]cn C |
| sha256 | 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 | ocessFolderPath C:\ProgramData\.exe InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 InitiatingProcessCommandLine ".exe" InitiatingProcessCreati |
| sha256 | 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 | ogram Files (x86)\72q1o6\40gK5T.exe InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 InitiatingProcessCommandLine "40gK5T.exe" InitiatingProcess |
| url | http://www.gehie246[ | e indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down pc-razerzone[.]com[.]cn → hxxp://www.gehie246[ |
Full article2,377 words · extracted from microsoft.com · click to collapse

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor. Microsoft Defender detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption. Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.
Attack chain overview
The campaign follows a consistent attack chain from a spoofed vendor download page to a self-protecting, persistent implant. The stages below trace that chain — initial access, delivery, execution, persistence, privilege escalation, defense evasion, and command and control.
Figure 1. Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.
Campaign scope and targeting
Microsoft observed affected devices predominantly associated with China-based operations and Chinese-speaking users, consistent with the Chinese-language lure content and the .com.cn and .hl.cn infrastructure. Confirmed activity spans medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education across multiple organizations and industries.
Initial access: spoofed software-download sites
The entry point is a fraudulent software-download website that spoofs a legitimate vendor. In one case, endpoint telemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down ; two content-distinct copies of the same-named archive were written within roughly 69 seconds — a direct observation of server-side payload regeneration.
Across the estate, FileOriginReferrerUrl telemetry ties each downloaded archive to the impersonation page that served it and to rotating delivery hosts ( yimxg25tiy[.]com/73inst , cc8ttkv35b[.]com/7qinst , n7b8t85zsg[.]com/ins711 ) and a suspected attacker-controlled Alibaba Cloud Object Storage Service (OSS) bucket. The lure domains predominantly use .com.cn , .hl.cn , and .cn and embed the impersonated brand name.
Delivery: a dynamically generated installer archive
The following examples illustrate how look-alike domains routed users to the same delivery infrastructure while preserving brand-specific lure pages.
When the user selects the download control, Microsoft Edge retrieves a malicious installer archive from a small set of dedicated delivery domains.
pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader
A defining characteristic is that the archive keeps the same filename while its hash changes on every download — a strong indicator the payload is generated server-side, per request. Microsoft observed families of same-named archives ( app_setup.* , zinst.* , zintall.* , intsoft.* , innstll.* ) whose contents differ across downloads while the delivery URL stays constant; the full validated hash set is in the indicators of compromise below.
kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down
pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down
calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down
Brand-impersonation infrastructure
The campaign runs a large, uniform set of vendor look-alike pages on .com.cn and .hl.cn domains, each cloning the real product’s branding and presenting a prominent “Download now” button. All funnel to the same delivery and payload infrastructure.
Impersonated brand Spoofed domain (defanged) Category
Razer (Synapse driver) pc-razerzone[.]com[.]cn Peripherals / drivers
Microsoft Edge app-microsoft-edge[.]com[.]cn Browser
Kaspersky kaspersky-lab[.]hl[.]cn Security software
Sejda PDF sejda[.]hl[.]cn Productivity
NetEase Youdao Dictionary translate-youdao[.]hl[.]cn Translation
DiskGenius zh-diskgenius[.]com[.]cn Disk utility
Baidu Netdisk (Pan) baidu-pan[.]com[.]cn Cloud storage
oCam Screen Recorder ocam-pc[.]com[.]cn Screen capture
draw.io cn-drawio[.]com[.]cn Diagramming
SteelSeries steelseries-cn[.]com[.]cn Peripherals
Sogou gw-sogou[.]com[.]cn Input method
Calibre calibre-ebook[.]com[.]cn E-book
MindMaster (typosquat) mindmoster[.]com[.]cn Mind-mapping
Others pc-codex, jinshan-cibapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) Various utilities
Although these domains impersonate unrelated vendors, they are not independently hosted. Infrastructure enrichment, corroborated by Microsoft telemetry where the two overlap, resolves them into two groupings. Six domains resolve within AS132839, spread across four unrelated netblocks and three registered country codes, and share a common pair of nameservers. Two further domains resolve within AS8796 in a single /21, using a different nameserver pair. One additional domain is served through a content delivery network (CDN), concealing its origin. Because hosting and Domain Name System (DNS) are frequently bundled by the same reseller, these are best read as two consistent procurement channels rather than two independent corroborating signals.
The practical implication for defenders is that netblock- and geography-based grouping will miss these relationships, while Autonomous System Number (ASN)-level analysis surfaces them.The autonomous system remains constant even where the address space and registered country vary. These are shared commercial hosting and DNS providers carrying substantial unrelated tenancy, so the ASN and nameserver should be treated as hunting pivots, not blocklist entries.
The following capture shows a representative impersonation page served by the campaign. The pages are high-fidelity clones of a legitimate vendor’s site with a prominent download call-to-action.
Figure 2b. Counterfeit Microsoft Edge download page hosted on the look-alike domain app-microsoft-edge[.]com[.]cn, with a prominent download button.
Execution: a wrapped installer drops a randomized stage-one payload
The wrapper installer creates a randomized executable path while reusing stable payload content, making names unreliable but behavior and hashes useful for detection.
Opening the archive yields a wrapper installer whose name follows a generated pattern (for example, a_instapp83353001.exe or ainst8663586104.exe ).
Executing the wrapper creates and launches a stage-one payload at a randomized path under a world-writable or system location; the directory and file names are randomized, but the payload content is stable. The same stage-one 256-bit Secure Hash Algorithm (SHA-256) (676a2a7b94ca…) was observed under many names and paths.
C:\Users\Public\sE94yD\aLcUaw.exe (SHA-256 676a2a7b94ca… stage-one)
C:\Users\Public\nvdPX5\2b3L5i.exe (SHA-256 676a2a7b94ca… stage-one)
C:\Program Files (x86)\i3LH90\ErNGxW.exe (SHA-256 6d6ba2bc9ad4… later-stage)
C:\Program Files (x86)\Q8Maj\7EIr6VA.exe (SHA-256 6d6ba2bc9ad4… later-stage)
C:\ProgramData\zsMmvukD\beuv4Mie.exe (SHA-256 c6100166e2d3… persistent)
The end-to-end chain is visible as a parent-to-child process tree: msedge.exe writes the archive, an archiving tool ( 7zFM.exe , 360zip.exe , or WinRAR.exe ) extracts it, the bundled wrapper runs, and the wrapper launches the randomized stage-one payload.
msedge.exe downloads app_setup.6653004.zip
└─ 7zFM.exe / 360zip.exe / WinRAR.exe (user opens the downloaded archive)
└─ a_instapp83353001.exe (wrapper installer bundled in the archive)
└─ C:\Users\Public\yZ6A88\9bEELI.exe (stage-one payload, randomized)
Payloads are masqueraded; Microsoft confirmed the masquerade through file metadata on the later-stage payload (SHA-256 6d6ba2bc…), staged at C:\Program Files (x86)\<random>\ . The binary’s version resource declares CompanyName: “Speech Processing Solutions GmbH”, FileDescription: “Philips Speech Driver Client Configuration”, OriginalFileName: PhilipsSpeechDriverConfiguration.exe, and ProductVersion: 4.7.471.07,while executing from a randomized directory under a randomized file name. The same resource retains an unfilled build-template placeholder, ProductName: “TODO: <Product name>”, indicating the version information was fabricated for the payload rather than inherited from genuine vendor software. Microsoft also observed svchost.exe executing from a non-system path ( D:\hellothere\svchost.exe ) rather than C:\Windows\System32 .
FileName XPSPLOG.dll
FolderPath C:\Program Files (x86)\72q1o6\XPSPLOG.dll
InitiatingProcessFileName 40gK5T.exe
InitiatingProcessFolderPath C:\Program Files (x86)\72q1o6\40gK5T.exe
InitiatingProcessSHA256 6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8
InitiatingProcessCommandLine "40gK5T.exe"
InitiatingProcessVersionInfoCompanyName Speech Processing Solutions GmbH
InitiatingProcessVersionInfoFileDescription Philips Speech Driver Client Configuration
InitiatingProcessVersionInfoOriginalFileName PhilipsSpeechDriverConfiguration.exe
InitiatingProcessVersionInfoProductVersion 4.7.471.07
InitiatingProcessVersionInfoProductName TODO:
InitiatingProcessParentFileName svchost.exe
A payload staged under C:\ProgramData\<random>\ (SHA-256 c6100166…) carries the version metadata of the Indigo Rose TrueUpdate Client (OriginalFileName: tu_rt.exe, ProductVersion: 3.8.0.0) and exhibits that product’s runtime behavior, writing _ir_tu2_temp_* artifacts to the user’s temp directory on each execution. Dropped by the later-stage payload and launched repeatedly by the Task Scheduler service, it connects to an attacker-controlled Alibaba Cloud OSS bucket over Transport Layer Security (TLS) and writes a further payload to a second randomized C:\ProgramData\ directory — a legitimate update mechanism repurposed for payload delivery.
00:24:43 ErNGxW.exe (6d6ba2bc…) creates C:\ProgramData\zsMmvukD\beuv4Mie.exe (c6100166…)
00:24:43 beuv4Mie.exe executes ← parent: svchost.exe -k netsvcs -p -s Schedule
00:24:44 beuv4Mie.exe → ConnectionSuccess | upitem.oss-cn-hangzhou.aliyuncs.com | 443
00:24:44 beuv4Mie.exe creates C:\ProgramData\uwMUCYBN\SaYC4Mga.exe (f33d160d…)
02:12:22 beuv4Mie.exe creates …\Temp\_ir_tu2_temp_4 ← TrueUpdate runtime artifact
02:44:20 beuv4Mie.exe re-executes (scheduled task) → _ir_tu2_temp_5
02:59:00 … _temp_6 03:15:54 … _temp_7 08:02:52 … _temp_8
08:32:20 … _temp_9 08:38:51 … _temp_11
Wrapper installer Stage-one payload created
a_instapp83353001.exe C:\Users\Public\yZ6A88\9bEELI.exe
z_instapp83351010.exe C:\Users\Public\Y93eny\Ge86Zr.exe
ainstaller-86533003.exe C:\Users\Public\Mmzm0e\Lrrhwp.exe
ainst8663586104.exe C:\Users\Public\YJMvsB\BcQVw7.exe
Alternate execution vector: Windows Installer (msiexec)
In parallel with the wrapped-installer chain, Microsoft observed a second execution vector that uses the Windows Installer service. The installer performs its intended function; what the campaign gains is execution under a signed, trusted Windows component. The extracted installer invokes msiexec.exe in embedded mode, which writes and launches a randomized executable into a world-writable C:\Users\Public\<random>\ directory, the same masquerade pattern as the wrapper chain, but delivered through msiexec.exe .
msiexec.exe -Embedding E Global\MSI0000
└─ C:\Users\Public\\.exe (payload, randomized path/name)
The behavior is consistent and repeated: more than twenty distinct payload names were written this way, spawned by a range of parents including msedge.exe , explorer.exe , and svchost.exe .
Persistence and recurring execution: disguised scheduled tasks
Persistence and recurring execution are achieved through scheduled tasks whose display names imitate routine IT or productivity jobs (for example “Deadline Mission Target” and “Hierarchy Tools Smooth Inventory”), each launching a specific payload staged under C:\ProgramData\ .
Each task launches a specific payload:
Scheduled task name Payload launched
\Deadline Mission Target 7fYptijy.exe
\Hierarchy Tools Smooth Inventory beuv4Mie.exe
\Empowering Status Tools productivity Ahead SaYC4Mga.exe
\5nboF aLcUaw.exe (stage-one)
The persistent payloads are staged in locations such as C:\ProgramData\7fYptijy.exe , C:\ProgramData\zsMmvukD\beuv4Mie.exe , and C:\ProgramData\uwMUCYBN\SaYC4Mga.exe . Because the payloads are launched by the Task Scheduler service (parented to svchost.exe -k netsvcs -p -s Schedule ) and multiple staggered tasks run per device, affected hosts exhibit a characteristic ~60-second re-execution cadence.
Privilege escalation: SYSTEM scheduled task and process injection
To perform privileged actions such as writing Microsoft Defender exclusions, the malware creates a short-lived scheduled task that runs as SYSTEM ( SCHTASKS /Create … /RL HIGHEST /RU “SYSTEM” ), executes the privileged action, then immediately runs and deletes the task
SCHTASKS /Create /F /TN "Task1" /SC ONCE /ST 00:00 /RL HIGHEST /RU "SYSTEM"
/TR "cmd.exe /c reg add \"HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\"
/v \"C:\Program Files (x86)\NPq6k16Om\" /t REG_DWORD /d 0 /f"
SCHTASKS /Run /TN "Task1" & SCHTASKS /Delete /TN "Task1" /F
The /RL HIGHEST /RU “SYSTEM” combination elevates the exclusion write to SYSTEM, and the create-run-delete sequence minimizes the footprint of the helper task. Process injection was also observed. A persistent campaign payload (SHA-256 1bd3662d…), launched from C:\ProgramData\ by the Task Scheduler service, created a remote thread in a legitimate user application moments after that application started — executing payload code inside the context of a trusted process. Microsoft Defender detected the activity as A process was injected with potentially malicious code .
ActionType CreateRemoteThreadApiCall
InitiatingProcessFileName .exe
InitiatingProcessFolderPath C:\ProgramData\.exe
InitiatingProcessSHA256 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17
InitiatingProcessCommandLine ".exe"
InitiatingProcessCreationTime 2026-07-13 02:44:20.887
InitiatingProcessParentFileName svchost.exe
FileName .exe (target process)
ProcessCommandLine ".exe" -autorun
ProcessCreationTime 2026-07-13 02:44:37.568
AdditionalFields {"IntegrityLevel":8192}
The sequence below shows a single execution cycle end to end: the Task Scheduler service launches the payload, the payload immediately attempts command-and-control on two non-standard ports — both blocked at the host firewall — and, seventeen seconds later, injects into a user application within milliseconds of that application starting.
02:44:20.887 PROC .exe started parent: svchost.exe (Task Scheduler)
02:44:21.971 NETWORK outbound to 47.239.232[.]245:8050 → FirewallOutboundConnectionBlocked
02:44:24.860 NETWORK outbound to 47.243.218[.]255:28300 → FirewallOutboundConnectionBlocked
02:44:37.568 PROC target application starts (-autorun)
02:44:37.604 INJECT CreateRemoteThreadApiCall .exe → target application
Defense evasion: disabling host protections
Follow-on payloads take a layered approach to weakening the host. They add sweeping Microsoft Defender path exclusions via PowerShell ( Add-MpPreference -ExclusionPath ) and the SYSTEM scheduled-task registry write;
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/