[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTaxzSahsWeIkwapCejvq105DxBpckBnI0NO0UfFSM-s":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"4627d21c-355b-4c42-8837-c6a4afa2235d","fake-installers-sabotage-windows-update-and-defender-to-persist-undetected","4e4390bc-5dc4-4f10-94e6-5fdd258d050f","Fake Installers Sabotage Windows Update and Defender to Persist Undetected","Attackers are distributing trojanized software installers through fraudulent download sites, tricking users into running malware that deliberately disables Windows Update and degrades Microsoft Defender protections. This campaign, attributed to the Chinese threat cluster Silver Fox, exploits the common user behavior of seeking free or convenient software downloads from unverified sources. By crippling built-in defenses first, the malware ensures it can establish persistence and communicate with attacker infrastructure without triggering OS-level alerts. This matters because once core security controls like automatic patching and antivirus are neutralized, the victim's system becomes significantly easier to exploit further. Organizations that do not enforce software installation policies or monitor security configuration changes are especially vulnerable.","**Immediate actions:**\n- Block unapproved software download sites at the DNS\u002Fweb proxy layer to prevent users from reaching fake installer pages.\n- Audit endpoints for unexpected changes to Windows Update settings and Microsoft Defender configurations using endpoint management tools.\n- Enable tamper protection in Microsoft Defender to prevent unauthorized modification of security settings.\n\n**Long-term improvements:**\n- Enforce application allowlisting so only approved, signed software installers can execute on corporate endpoints.\n- Implement a formal software procurement policy requiring all installations to originate from verified, official vendor sources.\n- Restrict standard user accounts from modifying system security configurations using Group Policy or equivalent controls.\n\n**Detection measures:**\n- Alert on registry or Group Policy changes that disable Windows Update or weaken antivirus settings as high-priority security events.\n- Deploy behavioral EDR solutions to detect processes that attempt to tamper with security tooling or establish unusual outbound C2 connections.\n- Integrate threat intelligence feeds tracking Silver Fox and similar clusters to proactively identify associated indicators of compromise.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 7: Continuous Vulnerability Management","CIS Control 10: Malware Defenses","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","NIST SP 800-53 SA-12: Supply Chain Protection","NIST CSF PR.IP-1: Baseline Configuration","MITRE ATT&CK T1562.001: Impair Defenses – Disable or Modify Tools","MITRE ATT&CK T1195: Supply Chain Compromise","published","2026-09-02T18:20:50.280193+00:00","2026-09-02T18:20:49.991+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ffake-software-installers-disable.html","fake-software-installers-disable-windows-update-and-weaken-microsoft-defender-64ac10","Fake Software Installers Disable Windows Update and Weaken Microsoft Defender",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]