Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Fake Software Installers Turn Malicious: Disabling Windows Update and Weakening Microsoft Defender




A recent malicious campaign has been discovered that impersonates trusted vendors to distribute fake software installers, which deploy malware that disables Windows Update and weakens Microsoft Defender. The campaign, dubbed "Silver Fox," targets users looking to download popular software, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. The malware achieves persistence through scheduled tasks and configures Microsoft Defender exclusions via PowerShell, leading to significant security concerns. The end goal of the campaign remains unclear, but experts warn of the potential consequences of such malicious activity.

  • Cybersecurity experts have discovered a sophisticated malicious campaign impersonating trusted vendors to distribute fake software installers.
  • The malware, identified as part of the "Silver Fox" threat cluster, uses spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT.
  • The campaign has targeted users looking to download popular software, primarily affecting China-based operations and Chinese-speaking users.
  • The malware achieves persistence through scheduled tasks and modifies system settings to prevent removal by standard users.
  • The campaign establishes command-and-control (C2) over non-standard ports and uses C2 domains to communicate with attacker-controlled infrastructure.
  • The end goal of the campaign is unclear, but it has been used in conjunction with other malware, such as QN Wallpaper and ValleyRAT.
  • The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, complicating detection.
  • The malware is not unique to any actor, but has been known to be used by GoldenEyeDog.



  • In a recent revelation, cybersecurity experts have discovered a sophisticated malicious campaign that has been impersonating trusted vendors to distribute fake software installers. These installers, once launched, deploy malware that sets up persistence, weakens security protections, and communicates with attacker-controlled infrastructure. The campaign, which has targeted users looking to download popular software, has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users.

    The malware, which has been identified as part of the "Silver Fox" threat cluster, dubbed "Yinhu," has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (aka WinOS 4.0). The websites observed as part of the campaign are hosted on the .com.cn and .hl.cn infrastructure and use Chinese-language lure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites include app-microsoft-edge[.]com[.]cn, baidu-pan[.]com[.]cn, calibre-ebook[.]com[.]cn, cn-drawio[.]com[.]cn, gw-sogou[.]com[.]cn, kaspersky-lab[.]hl[.]cn, mindmoster[.]com[.]cn, ocam-pc[.]com[.]cn, pc-razerzone[.]com[.]cn, sejda[.]hl[.]cn, steelseries-cn[.]com[.]cn, translate-youdao[.]hl[.]cn, and zh-diskgenius[.]com[.]cn.

    The web pages are high-fidelity clones of the legitimate vendor's site and feature a prominent download call-to-action. Tellingly, the archive downloaded from the site maintains the same file name while its hash changes on every download, indicating that the payload is generated server-side on the fly for every request. Opening the archive leads to a wrapper installer, which, upon execution, launches the first stage payload. Separately, Microsoft said it observed a second execution vector that makes use of the trusted Windows Installer service ("msiexec.exe") to launch a randomized executable, mirroring the same masquerade pattern as the wrapper chain.

    Regardless of the method used, persistence is achieved through scheduled tasks that imitate routine IT or productivity jobs. The malware is also responsible for creating a short-lived scheduled task that runs as SYSTEM and configures Microsoft Defender exclusions via PowerShell, deletes volume shadow copies, and ensures payload directories cannot be removed by standard users by modifying their discretionary access control lists (DACLs) using icacls.

    In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update dynamic-link libraries (DLLs), and deleting the SoftwareDistribution cache. Once all these steps are carried out, the malware establishes command-and-control (C2) over application-layer protocols on non-standard ports like 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net."

    It is unclear what the end goal of the campaign is, as Microsoft said Defender detected and initiated automated containment procedures through attack disruption to limit the attack's impact further. The disclosure comes merely days after Kaspersky detailed a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, while using it to initiate a DLL sideloading chain responsible for delivering ValleyRAT.

    The backdoor, besides taking steps to protect its process and prevent it from being terminated, captures keystrokes and clipboard contents, and saves the contents to a file on disk. It also periodically scans for active windows belonging to applications that could be used to analyze processes or traffic. ValleyRAT is a sophisticated implant with a wide range of features that allows it to collect system information, reboot/shut down the computer, take screenshots, wipe logs, update C2 addresses, download additional DLL or shellcode modules, and send keylogger logs along with clipboard data.

    The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection. Motivated by both cyber espionage and financial gain, Silver Fox targets organizations across multiple countries. According to a report published by Expel last month, the use of ValleyRAT has also been attributed to a sub-group within GoldenEyeDog known as CuboidalCanine, which is assessed to have moved away from Gh0st RAT "at some point." CuboidalCanine, per the cybersecurity company, targets the gambling industry and uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls.

    This malware isn't unique to any actor, but has been known to be used by GoldenEyeDog. Due to the source code being public, attribution of this malware to any actor relies on factors other than the malware family itself. In June 2026, Chinese authorities took action against a series of cybercrime cases distributing a new variant of the Silver Fox trojan, state media outlet China Daily reported.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Fake-Software-Installers-Turn-Malicious-Disabling-Windows-Update-and-Weakening-Microsoft-Defender-ehn.shtml

  • https://thehackernews.com/2026/09/fake-software-installers-disable.html


  • Published: Wed Sep 2 15:30:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us