Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.
Description
A malware campaign tracked by Microsoft Defender Experts uses counterfeit websites impersonating trusted software vendors to trick users into executing malicious installers. Once executed, the malware establishes persistence and manipulates Windows Defender through PowerShell scripts to set scan exclusions and disable Windows Update. The campaign has compromised organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, with focus on China-based operations of multinational companies and Chinese-speaking users. Threat Intelligence also observes a related campaign abusing Microsoft Teams to impersonate IT support.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 7.00
- vendor mismatch penalty
- 0.00
- consensus penalty
- -8.00
Path: operational
Consensus check
The pipeline self-checks before delivery. These rules lowered the score:
-
TTP_MISMATCHATT&CK techniques in text absent from structured mapping −8
- Consensus penalty:
- −8.0
- Total penalty:
- −8.0
MITRE ATT&CK mapping
5 TTPsProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1583.001 | Technique T1583.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1583.006 | Technique T1583.006 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1204.002 | Technique T1204.002 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1059.001 | Technique T1059.001 explicitly referenced in source: Microsoft Security Blog | high | primary | |
| T1059.003 | Technique T1059.003 explicitly referenced in source: Microsoft Security Blog | high | primary |