Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

0
Medium
Published: 09/02/2026 (09/02/2026, 02:57:18 UTC)
Source: AlienVault OTX General

Description

A malware campaign uses counterfeit software-download websites impersonating trusted vendors to distribute malicious installers. The activity primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Malicious installers deploy payloads that establish persistence, disable security protections, and communicate with attacker-controlled infrastructure. The campaign employs dynamically generated installers with rotating hashes, spoofed vendor pages on .com.cn and .hl.cn domains, and randomized payload staging paths. Follow-on activity includes disabling Windows Defender, deleting shadow copies, neutralizing Windows Update, creating scheduled tasks for persistence, and establishing command-and-control over non-standard ports. Microsoft assesses this activity aligns with publicly reported Silver Fox operations but has not attributed it to a nation-state actor.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign"]
Adversary
Void Arachne
Pulse Id
6a97908e94bd394c915c1cb9
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash5251b98614acffe5c856f4039ca03da3
hashc80ed6716e89d4862f28ebbc130ec5aa362db963
hash6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8
hash9ec587911e501b73b7cf09f05d0ae17d
hash5b62403cc9a668c6e5c70ace177fd54fcc4c5936
hash676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7
hashc4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdf
hash1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17
hashc6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73faf
hashf33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81b
hashe4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3

Domain

ValueDescriptionCopy
domainiualef.net
domainczijbh.net
domaintbdqxq.net
domainwfmwsj.net
domaingehie246.com
domainbaidu-pan.com.cn
domainsteelseries-cn.com.cn
domainpc-razerzone.com.cn
domainyimxg25tiy.com
domaincc8ttkv35b.com
domainn7b8t85zsg.com
domainkaspersky-lab.hl.cn
domaincalibre-ebook.com.cn
domainapp-microsoft-edge.com.cn
domainsejda.hl.cn
domaintranslate-youdao.hl.cn
domainzh-diskgenius.com.cn
domainocam-pc.com.cn
domaincn-drawio.com.cn
domaingw-sogou.com.cn
domainmindmoster.com.cn
domaineuioxu.net
domainoijfwe.net
domainbxfh.tzcdq.cn
domaintmsq.tzcdq.cn
domainmebx78e02.com
domainqwjre1487.com
domainwww.gehie246.com

Ip

ValueDescriptionCopy
ip161.248.87.157
ip202.95.14.237
ip103.156.25.35
ip103.183.3.162

Url

ValueDescriptionCopy
urlhttps://www.gehie246.com/712down
urlhttp://www.gehie246.com/712down
urlhttp://cc8ttkv35b.com/7qinst
urlhttp://gehie246.com/712down
urlhttp://n7b8t85zsg.com/ins711
urlhttp://yimxg25tiy.com/73inst

Threat ID: 6a980a7aacd9273b492f5450

Added to database: 09/02/2026, 11:37:30 UTC

Last updated: 09/02/2026, 12:38:50 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses