Back to all lessons
Awareness Lessons
last month

Fake Installers Sabotage Windows Update and Defender to Persist Undetected

Attackers are distributing trojanized software installers through fraudulent download sites, tricking users into running malware that deliberately disables Windows Update and degrades Microsoft Defender protections. This campaign, attributed to the Chinese threat cluster Silver Fox, exploits the common user behavior of seeking free or convenient software downloads from unverified sources. By crippling built-in defenses first, the malware ensures it can establish persistence and communicate with attacker infrastructure without triggering OS-level alerts. This matters because once core security controls like automatic patching and antivirus are neutralized, the victim's system becomes significantly easier to exploit further. Organizations that do not enforce software installation policies or monitor security configuration changes are especially vulnerable.

Tactical Insight

Immediate actions

  • Block unapproved software download sites at the DNS/web proxy layer to prevent users from reaching fake installer pages.
  • Audit endpoints for unexpected changes to Windows Update settings and Microsoft Defender configurations using endpoint management tools.
  • Enable tamper protection in Microsoft Defender to prevent unauthorized modification of security settings.

Long-term improvements

  • Enforce application allowlisting so only approved, signed software installers can execute on corporate endpoints.
  • Implement a formal software procurement policy requiring all installations to originate from verified, official vendor sources.
  • Restrict standard user accounts from modifying system security configurations using Group Policy or equivalent controls.

Detection measures

  • Alert on registry or Group Policy changes that disable Windows Update or weaken antivirus settings as high-priority security events.
  • Deploy behavioral EDR solutions to detect processes that attempt to tamper with security tooling or establish unusual outbound C2 connections.
  • Integrate threat intelligence feeds tracking Silver Fox and similar clusters to proactively identify associated indicators of compromise.