Deceptive Software Campaign Exposed
A routine software search recently transformed into a critical entry point for severe malware infections. Microsoft recently exposed a sophisticated counterfeit installer campaign. Participants in this operation meticulously cloned the websites of renowned software developers. They subsequently distributed highly malicious installers through these deceptive platforms. This dangerous campaign primarily targeted Chinese-speaking users and the regional branches of multinational corporations operating within China.
Sophisticated Imitation Tactics
The fraudulent web pages expertly mimicked official sites for popular software. Targets included Razer, Microsoft Edge, Kaspersky, Sejda PDF, DiskGenius, Baidu Netdisk, draw.io, and Calibre. Upon clicking the download button, the victim’s browser received a ZIP archive containing the malicious installer. While seemingly independent, all these fraudulent pages funneled unsuspecting visitors toward a centralized, shared delivery infrastructure.
Dynamic Malware Generation
The contents of the downloaded archive altered dynamically with every single request. The visible filename and download address remained deceptively constant. Microsoft analysts firmly believe the server generated a completely new software build for every unique request. This dynamic generation significantly complicated threat hunting efforts relying on traditional checksum verification. Based on the operational characteristics, experts cautiously attribute this activity to the notorious Silver Fox campaign, also known as Yinhu.
Deep System Penetration and Evasion
Following execution, the installer deposited files under randomized names within public and vital Windows system directories. The malware subsequently entrenched itself utilizing heavily disguised Task Scheduler entries. It aggressively escalated privileges to the SYSTEM level and covertly injected code directly into trusted processes. One specific component exploited the legitimate TrueUpdate mechanism to retrieve its next payload directly from Alibaba Cloud storage.
Disabling Critical Defenses
The malware then systematically added its directories directly into the Microsoft Defender exclusion list. It ruthlessly deleted Volume Shadow Copies and completely disabled crucial Windows Update services. Distinct components established covert communication with command and control servers utilizing non-standard network ports. In several compromised organizations, Microsoft also detected manual, hands-on-keyboard activities by the operators. These operators actively attempted lateral movement toward adjacent computers utilizing the SMB protocol.
Mitigation and Prevention Strategies
Microsoft Defender successfully detected and automatically halted a significant portion of these infections. However, completely eradicating the deeply entrenched components required direct intervention from security specialists. To mitigate this significant risk, Microsoft strongly advises downloading software exclusively from verified, official websites. Administrators must enable SmartScreen, robust network protection, and tamper protection features. The company also strongly recommends continuously monitoring process behavior. This behavioral monitoring remains crucial because filenames, domains, and checksums change constantly in this campaign.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.