Microsoft: counterfeit software installers disable Defender and Windows Update (Silver Fox-linked)
Microsoft Security Blog (1 September 2026) details an active campaign of high-fidelity fake vendor download sites (.com.cn / .hl.cn lookalikes for brands including Microsoft Edge, Razer, Kaspersky, Sejda, Calibre and others) that serve ZIP installers whose hashes rotate per download. Payloads establish persistence via disguised scheduled tasks, write sweeping Microsoft Defender exclusions (including short-lived SYSTEM tasks), delete volume shadow copies, stop/disable Windows Update services (wuauserv, UsoSvc, uhssvc, WaaSMedicSvc), and C2 on non-standard ports (e.g. 5090, 7031–7090, 8050, 28290, 28300) plus six-character .net domains. A parallel path uses msiexec -Embedding. Microsoft assesses with moderate confidence consistency with the publicly reported Silver Fox (Yinhu) fake-software campaign but does not attribute a nation-state. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations / Chinese-speaking users. Primary mitigations Microsoft names: Tamper Protection, SmartScreen/network protection, hunt randomized drops under Public/ProgramData/Program Files (x86), and block look-alike ZIP download patterns.
- Product
- Windows endpoints (fake installer / Silver Fox-linked campaign)
- Exploited in Australia?
- unknown
- Patch to
- Enable Tamper Protection; restrict software downloads to vendor-official channels; hunt Defender exclusion writes, shadow-copy deletion, and Update-service disablement
Primary: Microsoft Security Blog (1 Sep 2026) · Vendor: Microsoft (vendor) · The Hacker News (2 Sep 2026)
