[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDVhuWVF4ce8FJWa4Z6dXyHsD3pfolBMnGhjUKmU1_SA":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"905ca006-8a44-426a-b882-6367ccc456f6","Counterfeit installers to system compromise: Tracking a deceptive software download campaign","counterfeit-installers-to-system-compromise-tracking-a-deceptive-software-downlo-7d2c7d","An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.","A malware campaign is impersonating legitimate software vendors with fake download pages and dynamically generated installer archives to distribute malware. The campaign, potentially linked to the Silver Fox (Yinhu) threat actor, primarily targets Chinese-speaking users and organizations in China, affecting sectors like healthcare, manufacturing, and government. Microsoft Defender has detected and disrupted the attacks, which aim to establish persistence and weaken security protections.","Malware campaign uses counterfeit software download sites to deliver malicious installers.","Share Link copied to clipboard! TagsMalwareContent typesResearchProducts and servicesMicrosoft DefenderMicrosoft Defender ExpertsTopicsActionable threat insightsThreat intelligence Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor. Microsoft Defender detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption. Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity. Attack chain overview The campaign follows a consistent attack chain from a spoofed vendor download page to a self-protecting, persistent implant. The stages below trace that chain — initial access, delivery, execution, persistence, privilege escalation, defense evasion, and command and control. Figure 1. Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control. Campaign scope and targeting Microsoft observed affected devices predominantly associated with China-based operations and Chinese-speaking users, consistent with the Chinese-language lure content and the .com.cn and .hl.cn infrastructure. Confirmed activity spans medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education across multiple organizations and industries. Initial access: spoofed software-download sites The entry point is a fraudulent software-download website that spoofs a legitimate vendor. In one case, endpoint telemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery host gehie246[.]com\u002F712down; two content-distinct copies of the same-named archive were written within roughly 69 seconds — a direct observation of server-side payload regeneration. Across the estate, FileOriginReferrerUrl telemetry ties each downloaded archive to the impersonation page that served it and to rotating delivery hosts (yimxg25tiy[.]com\u002F73inst, cc8ttkv35b[.]com\u002F7qinst, n7b8t85zsg[.]com\u002Fins711) and a suspected attacker-controlled Alibaba Cloud Object Storage Service (OSS) bucket. The lure domains predominantly use .com.cn, .hl.cn, and .cn and embed the impersonated brand name. Delivery: a dynamically generated installer archive The following examples illustrate how look-alike domains routed users to the same delivery infrastructure while preserving brand-specific lure pages. When the user selects the download control, Microsoft Edge retrieves a malicious installer archive from a small set of dedicated delivery domains. pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com\u002F712down → app_setup.6653004.zip → stage-one loader A defining characteristic is that the archive keeps the same filename while its hash changes on every download — a strong indicator the payload is generated server-side, per request. Microsoft observed families of same-named archives (app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.*) whose contents differ across downloads while the delivery URL stays constant; the full validated hash set is in the indicators of compromise below. kaspersky-lab[.]hl[.]cn → hxxp:\u002F\u002Fwww.gehie246[.]com\u002F712down pc-razerzone[.]com[.]cn → hxxp:\u002F\u002Fwww.gehie246[.]com\u002F712down calibre-ebook[.]com[.]cn → hxxp:\u002F\u002Fwww.gehie246[.]com\u002F712down Brand-impersonation infrastructure The campaign runs a large, uniform set of vendor look-alike pages on .com.cn and .hl.cn domains, each cloning the real product’s branding and presenting a prominent “Download now” button. All funnel to the same delivery and payload infrastructure. Impersonated brandSpoofed domain (defanged)CategoryRazer (Synapse driver)pc-razerzone[.]com[.]cnPeripherals \u002F driversMicrosoft Edgeapp-microsoft-edge[.]com[.]cnBrowserKasperskykaspersky-lab[.]hl[.]cnSecurity softwareSejda PDFsejda[.]hl[.]cnProductivityNetEase Youdao Dictionarytranslate-youdao[.]hl[.]cnTranslationDiskGeniuszh-diskgenius[.]com[.]cnDisk utilityBaidu Netdisk (Pan)baidu-pan[.]com[.]cnCloud storageoCam Screen Recorderocam-pc[.]com[.]cnScreen capturedraw.iocn-drawio[.]com[.]cnDiagrammingSteelSeriessteelseries-cn[.]com[.]cnPeripheralsSogougw-sogou[.]com[.]cnInput methodCalibrecalibre-ebook[.]com[.]cnE-bookMindMaster (typosquat)mindmoster[.]com[.]cnMind-mappingOtherspc-codex, jinshan-cibapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn \u002F [.]hl[.]cn)Various utilities Although these domains impersonate unrelated vendors, they are not independently hosted. Infrastructure enrichment, corroborated by Microsoft telemetry where the two overlap, resolves them into two groupings. Six domains resolve within AS132839, spread across four unrelated netblocks and three registered country codes, and share a common pair of nameservers. Two further domains resolve within AS8796 in a single \u002F21, using a different nameserver pair. One additional domain is served through a content delivery network (CDN), concealing its origin. Because hosting and Domain Name System (DNS) are frequently bundled by the same reseller, these are best read as two consistent procurement channels rather than two independent corroborating signals. The practical implication for defenders is that netblock- and geography-based grouping will miss these relationships, while Autonomous System Number (ASN)-level analysis surfaces them.The autonomous system remains constant even where the address space and registered country vary. These are shared commercial hosting and DNS providers carrying substantial unrelated tenancy, so the ASN and nameserver should be treated as hunting pivots, not blocklist entries. The following capture shows a representative impersonation page served by the campaign. The pages are high-fidelity clones of a legitimate vendor’s site with a prominent download call-to-action. Figure 2b. Counterfeit Microsoft Edge download page hosted on the look-alike domain app-microsoft-edge[.]com[.]cn, with a prominent download button. Execution: a wrapped installer drops a randomized stage-one payload The wrapper installer creates a randomized executable path while reusing stable payload content, making names unreliable but behavior and hashes useful for detection. Opening the archive yields a wrapper installer whose name follows a generated pattern (for example, a_instapp83353001.exe or ainst8663586104.exe). Executing the wrapper creates and launches a stage-one payload at a randomized path under a world-writable or system location; the directory and file names are randomized, but the payload content is stable. The same stage-one 256-bit Secure Hash Algorithm (SHA-256) (676a2a7b94ca…) was observed under many names and paths. C:\\Users\\Public\\sE94yD\\aLcUaw.exe (SHA-256 676a2a7b94ca… stage-one) C:\\Users\\Public\\nvdPX5\\2b3L5i.exe (SHA-256 676a2a7b94ca… stage-one) C:\\Program Files (x86)\\i3LH90\\ErNGxW.exe (SHA-256 6d6ba2bc9ad4… later-stage) C:\\P","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F09\u002F01\u002Fcounterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F03\u002FMS_Actional-Insights_Malware-ransomware-1.jpg","2026-09-01T22:48:28+00:00","2026-09-02T00:00:17.763653+00:00",8,[18,21,23,26,28,30],{"name":19,"type":20},"Silver Fox","threat_actor",{"name":22,"type":20},"Yinhu",{"name":24,"type":25},"Microsoft Defender","product",{"name":27,"type":25},"Microsoft Defender XDR",{"name":29,"type":25},"Microsoft Edge",{"name":31,"type":32},"Microsoft","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":33,"icon":35,"name":36,"slug":37},null,"Malware","malware",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52,56,59,62,64],{"type":53,"value":54,"context":55},"domain","pc-razerzone[.]com[.]cn","Spoofed Razer download site",{"type":53,"value":57,"context":58},"gehie246[.]com","Delivery host for malicious installer archive",{"type":53,"value":60,"context":61},"yimxg25tiy[.]com","Rotating delivery host",{"type":53,"value":63,"context":61},"cc8ttkv35b[.]com",{"type":53,"value":65,"context":61},"n7b8t85zsg[.]com"]