Counterfeit software installers disable Windows Update and Defender: Microsoft ties China-focused campaign to Silver Fox (Yinhu); Elastic separately details REVSTEALER modules…
Microsoft tracks an active counterfeit software-installer campaign against multinationals' China operations, assessing with moderate confidence that it matches the publicly reported Silver Fox (Yinhu) campaign: per-download generated installers,…
Microsoft Defender Experts is tracking an active campaign that compromises organizations through spoofed vendor download pages impersonating Microsoft Edge, Kaspersky, Razer, Baidu Netdisk, Calibre, draw.io and Sejda (brand lists vary slightly across the reports: Microsoft's blog lists Calibre, while CSO Online adds draw.io and Sejda), hosted on .com.cn and .hl.cn domains and funneled through shared delivery hosts such as gehie246[.]com and rotating domains. The installer archives keep the same filename while their hash changes on every download, indicating server-side, per-request payload generation that defeats file-based detection. The chain establishes persistence via SYSTEM-level scheduled tasks and abuse of msiexec.exe to launch randomized executables inside a Microsoft-signed process, then adds Defender exclusions, deletes volume shadow copies, locks payload directories via DACLs, and stops services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc, effectively disabling Windows Update; some hands-on-keyboard activity was observed. Command-and-control runs over non-standard ports such as 5090 and 7088-7090 via the domains iualef[.]net and oijfwe[.]net. Confirmed victims span healthcare, manufacturing, gaming, technology, logistics, government and education, predominantly China-based operations of multinationals and Chinese-speaking users. Microsoft assesses with moderate confidence that the activity matches the publicly reported Silver Fox (Yinhu) fake-software campaign, historically tied to Gh0st RAT and ValleyRAT, and has not attributed it to a nation-state actor. Related third-party context: Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT and assesses Silver Fox is motivated by both cyber espionage and financial gain, while Expel links ValleyRAT use to the GoldenEyeDog sub-group CuboidalCanine targeting gambling. Microsoft recommends SmartScreen, network protection, tamper protection and Defender XDR. In a separate but thematically similar thread, Elastic Security Labs identified four previously unreported executables tied to REVSTEALER, a commercial Windows infostealer sold since at least February 2026: ProManager, WinUpdate, SoftManager and LockAppHost. LockAppHost abuses CMSTP for elevation, adds Microsoft Defender exclusions, disables five Windows Update services and 13 scheduled tasks, and hides a crypto miner in legitimate Windows processes; the other modules steal wallets, clipboard-swap crypto…
- Microsoft assesses with moderate confidence that the campaign matches the publicly reported Silver Fox (Yinhu) fake-software campaign; it has not attributed it to a nation-state actor.
- Spoofed download pages impersonate Microsoft Edge, Kaspersky, Razer, Baidu Netdisk, Calibre, draw.io and Sejda (brand lists differ between Microsoft's blog and CSO Online) on .com.cn and .hl.cn domains, funneling through shared delivery…
- Installer archives keep the same filename while the hash changes on every download, indicating per-request server-side payload generation.
- Persistence uses SYSTEM-level scheduled tasks; a second execution vector abuses msiexec.exe to launch randomized executables inside a Microsoft-signed process.
- The malware adds Defender exclusions, deletes volume shadow copies, locks payload directories via DACLs, and stops services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc, disabling Windows Update.
- C2 occurs over non-standard ports such as 5090 and 7088-7090 via the domains iualef[.]net and oijfwe[.]net.
- Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, predominantly China-based operations of multinationals and Chinese-speaking users; some hands-on-keyboard activity was observed.
- Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT and assesses Silver Fox is motivated by both cyber espionage and financial gain; Expel links ValleyRAT use to the GoldenEyeDog sub-group CuboidalCanine…
Coverage timelineoldest first · each row is one article
- · 15d agoCounterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Security Blog· 63
Microsoft tracks a counterfeit software-installer campaign compromising multinationals' China operations, moderately linked to the Silver Fox (Yinhu) actor.