Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.
Indicators of Compromise
- domain: iualef.net
- domain: gehie246.com
- domain: baidu-pan.com.cn
- domain: steelseries-cn.com.cn
- domain: pc-razerzone.com.cn
- domain: kaspersky-lab.hl.cn
- domain: calibre-ebook.com.cn
- domain: app-microsoft-edge.com.cn
- domain: sejda.hl.cn
- domain: translate-youdao.hl.cn
- domain: zh-diskgenius.com.cn
- domain: ocam-pc.com.cn
- domain: cn-drawio.com.cn
- domain: gw-sogou.com.cn
- domain: mindmoster.com.cn
- domain: oijfwe.net
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Description
An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://thehackernews.com/2026/09/fake-software-installers-disable.html"]
- Adversary
- Void Arachne
- Pulse Id
- 6a992140547fc1034bef07a8
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainiualef.net | — | |
domaingehie246.com | — | |
domainbaidu-pan.com.cn | — | |
domainsteelseries-cn.com.cn | — | |
domainpc-razerzone.com.cn | — | |
domainkaspersky-lab.hl.cn | — | |
domaincalibre-ebook.com.cn | — | |
domainapp-microsoft-edge.com.cn | — | |
domainsejda.hl.cn | — | |
domaintranslate-youdao.hl.cn | — | |
domainzh-diskgenius.com.cn | — | |
domainocam-pc.com.cn | — | |
domaincn-drawio.com.cn | — | |
domaingw-sogou.com.cn | — | |
domainmindmoster.com.cn | — | |
domainoijfwe.net | — |
Threat ID: 6a992751acd9273b49a066d1
Added to database: 09/03/2026, 07:52:49 UTC
Last updated: 09/03/2026, 15:19:41 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.