Search: “Windows Defender Application Control”
233 stories
Upatre Continued to Evolve with new Anti
Unit 42 analyzes an undocumented Upatre downloader variant with VM detection via process hashing, packed code, disabled Windows defenses and Namecoin .bit C2 domains.
Unit 42 analyzed an Upatre downloader variant compiled in December 2016 that went largely undetected by automated systems, featuring heavy code flow obscuration, on-demand decryption of network communications, and novel virtual machine detection. The sample enumerates running processes, computes CRC32 hashes XORed with a hard-coded key, and sleeps if analysis-related processes such as vmtoolsd.exe or python.exe are found. It masquerades with Google Chrome icons, disables Windows Defender, Firewall and other security services, injects code into msiexec.exe, and resolves .bit Namecoin domains like bookreader[.]bit via hardcoded OpenNIC DNS servers over TCP.
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Fake software-download sites distribute installers that disable Windows Update and weaken Defender, attributed to China-linked cluster Silver Fox.
Microsoft says an active campaign uses counterfeit vendor websites on .com.cn and .hl.cn infrastructure with Chinese-language lures to deliver server-side generated installers that establish scheduled-task persistence, add Defender exclusions, delete shadow copies, and stop services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations of multinationals and Chinese-speaking users. Microsoft assesses with moderate confidence the activity matches the Silver Fox (Yinhu) cluster, historically tied to Gh0st RAT and ValleyRAT, with C2 over non-standard ports like 5090 and 7088-7090 via domains iualef[.]net and oijfwe[.]net. Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic documents four persistent REVSTEALER-linked tools (ProManager, WinUpdate, SoftManager, LockAppHost); LockAppHost disables Windows Update and Defender to run a crypto miner.
Elastic Security Labs identified four previously unreported executables tied to REVSTEALER, a commercial Windows infostealer sold since at least February 2026: ProManager, WinUpdate, SoftManager, and LockAppHost. LockAppHost abuses CMSTP for elevation, adds Microsoft Defender exclusions, disables five Windows Update services and 13 scheduled tasks, then hides a miner in legitimate Windows processes; other modules steal wallets, clipboard-swap crypto addresses, and turn victims into reverse proxies. The components share REVSTEALER tradecraft including packer, runtime function resolution, and Polygon smart-contract backup configuration (EtherHiding). Elastic's detection rule matched about 4,700 VirusTotal samples over the past year; distribution uses hijacked YouTube channels promoting game cheats and a fake 'Claude Opus 5 Free Desktop' app.
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
Kaspersky details ValleyRAT delivered via trojanized QN Wallpaper using DLL sideloading, tied to Silver Fox and hitting 1,500+ users in China and India.
Kaspersky found a malicious installer abusing a modified version of the legitimate QN Wallpaper adware application to deliver the ValleyRAT backdoor via DLL sideloading of libcef.dll. The installer masquerades as DingTalk, Chrome or Tencent Meeting software, creates persistence, disables Windows Defender via the DisableAntiSpyware registry key, and loads AES-encrypted payloads. ValleyRAT collects keystrokes, clipboard contents and screenshots plus system details, can download additional modules, and resists removal by injecting into svchost.exe or marking its process critical. The campaign was detected over 100,000 times in 2026, affecting more than 1,500 users mainly in China and India, and is attributed to Silver Fox with both espionage and financial motives.
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Silver Fox distributes ValleyRAT via signed QN Wallpaper adware, sideloading a malicious libcef.dll into a trusted process to evade defenses.
Kaspersky reports the Silver Fox threat actor disguising the ValleyRAT backdoor (Winos 4.0) inside a modified, signed copy of the QN Wallpaper adware tool, using DLL sideloading to run within a trusted process. The installer disables Windows Defender via the DisableAntiSpyware registry key, adds autorun entries, and elevates via runas when needed; ValleyRAT steals keystrokes, clipboard data, and screenshots and can mark its process critical to trigger BSOD if killed. Kaspersky recorded more than 100,000 ValleyRAT detections affecting over 1,500 unique users in 2026, mostly in China and India, with prior campaigns against Japan, India, and Russia.