Skip to content
Auto-CTI
Back to today
NEW HIGH B3

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

B Microsoft Security Blog ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.

Description

A malware campaign tracked by Microsoft Defender Experts uses counterfeit websites impersonating trusted software vendors to trick users into executing malicious installers. Once executed, the malware establishes persistence and manipulates Windows Defender through PowerShell scripts to set scan exclusions and disable Windows Update. The campaign has compromised organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, with focus on China-based operations of multinational companies and Chinese-speaking users. Threat Intelligence also observes a related campaign abusing Microsoft Teams to impersonate IT support.

Risk score

Review required 12
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
0.50
exploitability factor
1.00
days old
7.00
vendor mismatch penalty
0.00
consensus penalty
-8.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_MISMATCH ATT&CK techniques in text absent from structured mapping −8
Consensus penalty:
−8.0
Total penalty:
−8.0

MITRE ATT&CK mapping

5 TTPs
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv. Escal.
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1583.001
Technique T1583.001 explicitly referenced in source: Microsoft Security Blog high primary
T1583.006
Technique T1583.006 explicitly referenced in source: Microsoft Security Blog high primary
T1204.002
Technique T1204.002 explicitly referenced in source: Microsoft Security Blog high primary
T1059.001
Technique T1059.001 explicitly referenced in source: Microsoft Security Blog high primary
T1059.003
Technique T1059.003 explicitly referenced in source: Microsoft Security Blog high primary
ESC