[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_Kgk5O5QigbTLOjRV-OUt7qp2Nu7jSLKGTGN17zwNiY":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"4e4390bc-5dc4-4f10-94e6-5fdd258d050f","Fake Software Installers Disable Windows Update and Weaken Microsoft Defender","fake-software-installers-disable-windows-update-and-weaken-microsoft-defender-64ac10","An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. \"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,\" Microsoft","A malware campaign is using fake software download websites to distribute malicious installers that disable Windows Update and weaken Microsoft Defender. The campaign, potentially linked to the Chinese threat cluster Silver Fox, targets users looking for popular software and has impacted various industries, primarily affecting China-based operations. The malware establishes persistence, modifies security settings, and communicates with attacker-controlled infrastructure.","Fake software installers are disabling Windows Update and weakening Microsoft Defender.","Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Ravie LakshmananSep 02, 2026Malware \u002F Social Engineering An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. \"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,\" Microsoft said. The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure. The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (aka WinOS 4.0). The websites observed as part of the campaign are hosted on the .com.cn and .hl.cn infrastructure and use Chinese-language lure content to trigger the download of a ZIP archive from \"gehie246[.]com.\" Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimate vendor's site and feature a prominent download call-to-action. Tellingly, the archive downloaded from the site maintains the same file name while its hash changes on every download, indicating that the payload is generated server-side on the fly for every request. Opening the archive leads to a wrapper installer (e.g., \"a_instapp83353001.exe\" or \"ainst8663586104.exe\"), which, upon execution, launches the first stage payload. Separately, Microsoft said it observed a second execution vector that makes use of the trusted Windows Installer service (\"msiexec.exe\") to launch a randomized executable, mirroring the same masquerade pattern as the wrapper chain. Regardless of the method used, persistence is achieved through scheduled tasks that imitate routine IT or productivity jobs. The malware is also responsible for creating a short-lived scheduled task that runs as SYSTEM and configures Microsoft Defender exclusions via PowerShell, deletes volume shadow copies, and ensures payload directories cannot be removed by standard users by modifying their discretionary access control lists (DACLs) using icacls. In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update dynamic-link libraries (DLLs), and deleting the SoftwareDistribution cache. Once all these steps are carried out, the malware establishes command-and-control (C2) over application-layer protocols on non-standard ports like 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains associated with the activity are \"iualef[.]net\" and \"oijfwe[.]net.\" It's unclear what the end goal of the campaign is, as Microsoft said Defender detected and initiated automated containment procedures through attack disruption to limit the attack's impact further. The disclosure comes merely days after Kaspersky detailed a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, while using it to initiate a DLL sideloading chain responsible for delivering ValleyRAT. \"The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user,\" Kaspersky said. \"In this case, however, the attackers use it to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL.\" The backdoor, besides taking steps to protect its process and prevent it from being terminated, captures keystrokes and clipboard contents, and saves the contents to a file on disk. It also periodically scans for active windows belonging to applications that could be used to analyze processes or traffic. ValleyRAT is a sophisticated implant with a wide range of features that allows it to collect system information, reboot\u002Fshut down the computer, take screenshots, wipe logs, update C2 addresses, download additional DLL or shellcode modules, and send keylogger logs along with clipboard data. \"The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection,\" Kaspersky said. \"Motivated by both cyber espionage and financial gain, Silver Fox targets organizations across multiple countries.\" According to a report published by Expel last month, the use of ValleyRAT has also been attributed to a sub-group within GoldenEyeDog known as CuboidalCanine, which is assessed to have moved away from Gh0st RAT \"at some point.\" CuboidalCanine, per the cybersecurity company, targets the gambling industry and uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls. \"This malware isn't unique to any actor, but has been known to be used by GoldenEyeDog,\" security researcher Aaron Walton said. \"Due to the source code being public, attribution of this malware to any actor relies on factors other than the malware family itself.\" In June 2026, Chinese authorities took action against a series of cybercrime cases distributing a new variant of the Silver Fox trojan, state media outlet China Daily reported. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Malware, Social Engineering, Web Security, Windows ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Bo","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ffake-software-installers-disable.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjhKCtgI2bIF4kLY71qjkluS80XAm5YPA9y9GzTxC8XBTaxq1d42jyZ-bxAr7OlZ-wCc4-RDp_NmUPKxd9TS1dvtjt3gysB86SkMuQ5q6vGb7HTh-DVMNC8VJcJFC2sJmiSQ740SX-miCoyiGfkAXLqO1ySH3zenWcAP7g6ilReO9jRsnl3Tnw279K7NYF3\u002Fs1600\u002Fwindows-updates.jpg","2026-09-02T16:41:06+00:00","2026-09-02T18:00:11.211048+00:00",9,[18,21,23],{"name":19,"type":20},"Silver Fox","threat_actor",{"name":22,"type":20},"Yinhu",{"name":24,"type":25},"Microsoft","vendor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":26,"icon":28,"name":29,"slug":30},null,"Malware","malware",[32,37,42,44],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":26,"icon":28,"name":29,"slug":30},{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[50,54,57,59,62,64,66,68,70,72,74,76,78,80,82,84],{"type":51,"value":52,"context":53},"domain","gehie246.com","Domain used to download malicious ZIP archives.",{"type":51,"value":55,"context":56},"iualef.net","Command and control (C2) domain associated with the campaign.",{"type":51,"value":58,"context":56},"oijfwe.net",{"type":51,"value":60,"context":61},"app-microsoft-edge.com.cn","Example of a counterfeit website domain.",{"type":51,"value":63,"context":61},"baidu-pan.com.cn",{"type":51,"value":65,"context":61},"calibre-ebook.com.cn",{"type":51,"value":67,"context":61},"cn-drawio.com.cn",{"type":51,"value":69,"context":61},"gw-sogou.com.cn",{"type":51,"value":71,"context":61},"kaspersky-lab.hl.cn",{"type":51,"value":73,"context":61},"mindmoster.com.cn",{"type":51,"value":75,"context":61},"ocam-pc.com.cn",{"type":51,"value":77,"context":61},"pc-razerzone.com.cn",{"type":51,"value":79,"context":61},"sejda.hl.cn",{"type":51,"value":81,"context":61},"steelseries-cn.com.cn",{"type":51,"value":83,"context":61},"translate-youdao.hl.cn",{"type":51,"value":85,"context":61},"zh-diskgenius.com.cn"]