Counterfeit installers and infostealers disable Windows Update, harvest AI agent tokens, and fuel MFA-bypassing LLMjacking
Microsoft-tracked Silver Fox campaign uses counterfeit Edge/Kaspersky/Razer download sites that disable Windows Update and weaken Defender; Elastic documents four REVSTEALER-linked modules, with LockAppHost disabling updates to hide a crypto miner; Gen…
Microsoft (reported by The Hacker News on 2026-09-02 and CSO Online on 2026-09-03) is tracking an active campaign breaching organizations in healthcare, manufacturing, gaming, technology, logistics, government and education — primarily the China-based operations of multinationals and Chinese-speaking users — via counterfeit vendor download pages on .com.cn and .hl.cn infrastructure using Chinese-language lures. The spoofed pages impersonate Microsoft Edge, Kaspersky, Razer, Baidu Netdisk, draw.io and Sejda. The delivered installers keep the same filename while their hash changes on every download, indicating per-request server-side payload generation that defeats file-based detection. They establish SYSTEM-level scheduled-task persistence, abuse msiexec.exe to launch randomized executables inside a Microsoft-signed process, add Microsoft Defender exclusions, delete volume shadow copies, lock payload directories via DACLs and stop Windows Update services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc; some hands-on-keyboard activity was observed. C2 runs over non-standard ports such as 5090 and 7088-7090 via iualef[.]net and oijfwe[.]net. Microsoft assesses with moderate confidence that the activity matches the Silver Fox (Yinhu) cluster — historically tied to Gh0st RAT and ValleyRAT, and described by The Hacker News as China-linked — while per CSO Online it has made no nation-state attribution. Kaspersky assesses Silver Fox is motivated by both cyber espionage and financial gain and separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT; Expel links ValleyRAT use to the GoldenEyeDog sub-group CuboidalCanine, which targets gambling. Elastic Security Labs (The Hacker News, 2026-09-06) documented four previously unreported executables tied to REVSTEALER, a commercial Windows infostealer sold since at least February 2026: ProManager, WinUpdate, SoftManager and LockAppHost. The modules persist after the self-deleting stealer but have not been observed on a live host. LockAppHost abuses CMSTP for elevation, adds Defender exclusions, disables five Windows Update services and 13 scheduled tasks and hides a crypto miner inside legitimate Windows processes; the other modules steal wallets, swap clipboard crypto addresses and turn victims into reverse proxies. The components share REVSTEALER tradecraft — packer, runtime function resolution, indirect syscalls, 10 sandbox checks, a Russia/Central Asia language exit and Polygon…
- Counterfeit download pages impersonate Microsoft Edge, Kaspersky, Razer, Baidu Netdisk, draw.io and Sejda, hosted on .com.cn and .hl.cn infrastructure with Chinese-language lures (Microsoft, per The Hacker News 2026-09-02 and CSO Online…
- Installers keep the same filename while the hash changes on every download, indicating per-request server-side payload generation; a second vector abuses msiexec.exe to launch randomized executables inside a Microsoft-signed process.
- The installers establish SYSTEM-level scheduled-task persistence, add Defender exclusions, delete volume shadow copies, lock payload directories via DACLs and stop Windows Update services including wuauserv, UsoSvc, uhssvc and…
- Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations of multinationals and Chinese-speaking users.
- C2 uses non-standard ports such as 5090 and 7088-7090 via iualef[.]net and oijfwe[.]net.
- Microsoft assesses with moderate confidence the activity matches the Silver Fox (Yinhu) cluster, historically tied to Gh0st RAT and ValleyRAT; The Hacker News describes Silver Fox as China-linked, while CSO Online notes Microsoft has made…
- Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT; Expel links ValleyRAT use to the GoldenEyeDog sub-group CuboidalCanine, which targets gambling.
- Elastic (2026-09-06) documented four previously unreported REVSTEALER-linked executables — ProManager, WinUpdate, SoftManager and LockAppHost; REVSTEALER is a commercial Windows infostealer sold since at least February 2026, and none of…
Coverage timelineoldest first · each row is one article
- · 13d agoFake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News· 68
Fake software-download sites distribute installers that disable Windows Update and weaken Defender, attributed to China-linked cluster Silver Fox.