Microsoft tracks counterfeit software download campaign targeting Chinese-speaking users
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor. Microsoft Defender detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption. Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.
Comments 0
Discuss this event in persistent threads. Live chat remains separate.
What we know
Microsoft assesses with moderate confidence that activity is consistent with the Silver Fox (Yinhu) campaign.
▤ 1 sources›
Microsoft Defender Experts is tracking an active malware campaign using counterfeit software-download websites.
▤ 1 sources›
Microsoft Defender detected and disrupted activity across multiple stages, including automated containment.
▤ 1 sources›
Malware establishes persistence, weakens security protections, and communicates with attacker-controlled infrastructure.
▤ 1 sources›
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
▤ 1 sources›
Affected devices are predominantly associated with China-based operations and Chinese-speaking users.
▤ 1 sources›
The campaign impersonates trusted vendors to distribute malicious installers.
▤ 1 sources›
Indicators of compromise and mitigations are provided.
▤ 1 sources›
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers, primarily affecting China-based operations and Chinese-speaking users across multiple sectors.
Verified · 1 sources
No comments yet. Start the conversation.