Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Strategic summary
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software download websites to impersonate trusted vendors and distribute malicious installers. The campaign primarily affects China-based operations of multinational organizations and Chinese-speaking users, with confirmed incidents across healthcare, manufacturing, gaming, technology, logistics, government, and education. It follows a consistent attack chain from spoofed download pages and dynamically generated installers to persistent malware that evades defenses and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox campaign, but has not attributed it to a nation-state actor.
Key findings
- Fraudulent download pages impersonate legitimate vendors such as Razer through domains like pc-razerzone.com.cn and redirect users to rotating delivery hosts, including a suspected attacker-controlled Alibaba Cloud OSS bucket.
- The malicious installers are dynamically regenerated server-side: two content-distinct copies of the same archive name were observed on a single device within 69 seconds.
- After execution, the malware establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure; Microsoft Defender automatically blocked and disrupted attack steps.
- Affected industries include healthcare, manufacturing, gaming, technology, logistics, government, and higher education, with China-based operations of multinational organizations and Chinese-speaking users primarily targeted.
- Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox campaign, without attribution to a nation-state actor.
Relevance for you
Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 7.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -8.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_MISMATCHATT&CK techniques in text absent from structured mapping −8
- Consensus penalty:
- −8.0
- Total penalty:
- −8.0
MITRE ATT&CK mapping
5 TTPsProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1583.001 | Technique T1583.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1583.006 | Technique T1583.006 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1204.002 | Technique T1204.002 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1059.001 | Technique T1059.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1059.003 | Technique T1059.003 explicitly referenced in source: Microsoft Security Blog | high | primary |