VMTech
Discuss a project

Counterfeit installers disable Windows Update in Silver Fox campaign

Counterfeit installers disable Windows Update in Silver Fox campaign

Microsoft identifies counterfeit download campaign

Microsoft has identified an active malware campaign in which bogus software-download websites impersonate trusted vendors and distribute malicious Windows installers. The activity has compromised organisations in multiple industries, with China-based operations of multinational organisations and Chinese-speaking users primarily affected.

Microsoft assessed with moderate confidence that the campaign is consistent with the Chinese threat cluster Silver Fox, also known as Yinhu. The group has previously used spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT, also called WinOS 4.0.

The affected sectors include healthcare, manufacturing, gaming, technology, logistics, government and education. Microsoft said the installers establish persistence, weaken endpoint protections and communicate with attacker-controlled infrastructure.

Payload chain targets security and recovery controls

The observed websites use Chinese-language lures and are hosted on .com.cn and .hl.cn infrastructure. They are high-fidelity clones of legitimate vendor sites, with prominent download prompts that deliver ZIP archives from gehie246[.]com.

The archive retains the same filename, but its hash changes with every download. Microsoft said this behaviour indicates that the payload is generated server-side for each request. When opened, the archive launches a wrapper installer, such as a_instapp83353001.exe or ainst8663586104.exe, which starts the first-stage payload.

Microsoft also observed a second execution route using the trusted Windows Installer service, msiexec.exe, to launch a randomly named executable. Both methods use scheduled tasks masquerading as ordinary IT or productivity jobs to maintain persistence.

A short-lived scheduled task running as SYSTEM configures Microsoft Defender exclusions through PowerShell, deletes volume shadow copies and changes discretionary access control lists with icacls to prevent standard users from removing payload directories. The malware also stops and disables wuauserv, UsoSvc, uhssvc and WaaSMedicSvc, renames Windows Update DLLs and deletes the SoftwareDistribution cache.

Network indicators and operational response

After these actions, the malware establishes command-and-control communications through application-layer protocols on non-standard ports, including 5090, 7031, 7032, 7088–7090, 8050, 28290 and 28300. Microsoft identified iualef[.]net and oijfwe[.]net as two C2 domains linked to the activity.

The campaign’s final objective remains unclear. Microsoft Defender detected the activity and initiated automated containment through attack disruption to limit its impact.

For businesses, the immediate implication is to keep software acquisition on approved channels and investigate unexpected scheduled tasks, Defender exclusions, disabled update services, altered update files and deleted shadow copies as potentially connected signs of compromise.

#cybersecurity#windowssecurity#malware#threatintel
Open analytics
On the site 0 views
min read 3 02.09.2026
Instagram

Counterfeit installers disable Windows Update in Silver Fox campaign

Open the post on Instagram ↗