Skip to content
Auto-CTI
Back to all deep dives
MICROSOFT SECURITY BLOG

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

HIGH counterfeit-installers malware-distribution social-engineering windows-compromise

Strategic summary

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software download websites to impersonate trusted vendors and distribute malicious installers. The campaign primarily affects China-based operations of multinational organizations and Chinese-speaking users, with confirmed incidents across healthcare, manufacturing, gaming, technology, logistics, government, and education. It follows a consistent attack chain from spoofed download pages and dynamically generated installers to persistent malware that evades defenses and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox campaign, but has not attributed it to a nation-state actor.

Key findings

  • Fraudulent download pages impersonate legitimate vendors such as Razer through domains like pc-razerzone.com.cn and redirect users to rotating delivery hosts, including a suspected attacker-controlled Alibaba Cloud OSS bucket.
  • The malicious installers are dynamically regenerated server-side: two content-distinct copies of the same archive name were observed on a single device within 69 seconds.
  • After execution, the malware establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure; Microsoft Defender automatically blocked and disrupted attack steps.
  • Affected industries include healthcare, manufacturing, gaming, technology, logistics, government, and higher education, with China-based operations of multinational organizations and Chinese-speaking users primarily targeted.
  • Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox campaign, without attribution to a nation-state actor.

Relevance for you

Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.

Risk score

Review required 12
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
7.00
vendor mismatch penalty
0.00
consensus penalty
-8.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_MISMATCH ATT&CK techniques in text absent from structured mapping −8
Consensus penalty:
−8.0
Total penalty:
−8.0

MITRE ATT&CK mapping

5 TTPs
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv. Escal.
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1583.001
Technique T1583.001 explicitly referenced in source: Microsoft Security Blog high primary
T1583.006
Technique T1583.006 explicitly referenced in source: Microsoft Security Blog high primary
T1204.002
Technique T1204.002 explicitly referenced in source: Microsoft Security Blog high primary
T1059.001
Technique T1059.001 explicitly referenced in source: Microsoft Security Blog high primary
T1059.003
Technique T1059.003 explicitly referenced in source: Microsoft Security Blog high primary
ESC