{"id":16670,"date":"2026-09-03T11:21:06","date_gmt":"2026-09-03T11:21:06","guid":{"rendered":"https:\/\/newestek.com\/?p=16670"},"modified":"2026-09-03T11:21:06","modified_gmt":"2026-09-03T11:21:06","slug":"counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16670","title":{"rendered":"Counterfeit installers turn routine software downloads into enterprise breaches"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOnce executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,\u201d Microsoft security researchers <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/01\/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">wrote<\/a> in a blog post.<\/p>\n<p class=\"wp-block-paragraph\">The campaign, tracked by Microsoft Defender Experts, has impacted organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education, the company said.<\/p>\n<p class=\"wp-block-paragraph\">The attackers are using a network of spoofed websites mimicking legitimate vendors, from browsers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious installers, the blog added.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft said the attack chain moves \u201cfrom a spoofed vendor download page to a self-protecting, persistent implant,\u201d turning routine software downloads into a reliable entry point for compromise.<\/p>\n<p class=\"wp-block-paragraph\">The company added that the activity is consistent with the publicly reported Silver Fox (also known as Yinhu) campaign, though it has \u201cnot attributed it to a nation-state actor.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"look-alike-sites-and-regenerating-payloads\">Look-alike sites and regenerating payloads<\/h2>\n<p class=\"wp-block-paragraph\">The attack begins with fraudulent download pages hosted on look-alike domains, often using <em>.com.cn<\/em> and <em>.hl.cn<\/em> naming patterns that embed the impersonated brand, according to the post.<\/p>\n<p class=\"wp-block-paragraph\">These pages route victims to a shared backend that delivers malicious installer archives. A key feature of the campaign is that the files \u201ckeep the same filename while its hash changes on every download,\u201d indicating server-side payload generation, Microsoft said.<\/p>\n<p class=\"wp-block-paragraph\">That significantly reduces the effectiveness of file-based detection, said Vibhum Dubey, a cybersecurity researcher and red teamer.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe installer keeps the same filename, but the hash changes with every download. So even if security teams identify and block one sample, the next download can be a different file.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"abuse-of-trusted-windows-components\">Abuse of trusted Windows components<\/h2>\n<p class=\"wp-block-paragraph\">Once executed, the installer launches a multi-stage infection chain, beginning with a wrapper that drops a payload to randomized locations on the system, the post said.<\/p>\n<p class=\"wp-block-paragraph\">In some cases, attackers also use the Windows Installer service to execute payloads through <em>msiexec.exe<\/em>, allowing malicious activity to run under a legitimate Microsoft-signed process, the researchers noted.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said that complicates detection because defenders must look beyond the binary itself.<\/p>\n<p class=\"wp-block-paragraph\">\u201cUsing msiexec.exe makes this harder because it is a legitimate, Microsoft-signed Windows component,\u201d he said. \u201cThe real question becomes why it was launched, where the MSI came from, and what happened after it ran.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added that the technique reflects a broader shift in attacker tradecraft, with adversaries increasingly blending into normal system behavior rather than relying on clearly malicious binaries.<\/p>\n<h2 class=\"wp-block-heading\" id=\"persistence-and-defense-evasion\">Persistence and defense evasion<\/h2>\n<p class=\"wp-block-paragraph\">After gaining execution, the malware establishes persistence using scheduled tasks that mimic routine system activity, repeatedly launching payloads, Microsoft said.<\/p>\n<p class=\"wp-block-paragraph\">The attackers then escalate privileges using short-lived scheduled tasks running as SYSTEM to modify Microsoft Defender settings, the post added.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft also observed multiple defense evasion techniques, including adding antivirus exclusions, deleting volume shadow copies, and disabling Windows Update services.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said the combination of these techniques is notable:<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe malware adds Defender exclusions, deletes shadow copies, interferes with Windows Update, and uses a temporary SYSTEM-level scheduled task.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThese actions show that the malware is thinking about the defender as well as the victim. It is trying to make detection harder, interfere with patching, and reduce the chances of recovery.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He added that while none of the techniques are new individually, combining them in a single chain point to more deliberate tooling.<\/p>\n<p class=\"wp-block-paragraph\">Later-stage payloads establish command-and-control communication using a mix of dedicated infrastructure and cloud services, including object storage used to stage additional payloads, Microsoft said.<\/p>\n<p class=\"wp-block-paragraph\">In some environments, the activity included \u201chands-on-keyboard\u201d actions, suggesting attackers may move beyond automated infection after gaining access, the post said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"enterprise-risk-and-detection-shift\">Enterprise risk and detection shift<\/h2>\n<p class=\"wp-block-paragraph\">The campaign highlights risks for multinational organizations, particularly where regional differences in software sourcing and IT practices exist.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor global organizations, China-based offices and subsidiaries can have different software sources, IT practices, and security policies. Those differences can create gaps that attackers can use,\u201d Dubey said.<\/p>\n<p class=\"wp-block-paragraph\">Because the fake sites closely mimic trusted vendors, users may not recognize the threat. \u201cAn employee may simply think they are downloading a familiar product and have no reason to suspect the installer,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft urged organizations to focus on behavioral indicators rather than file-based detection, noting that filenames and hashes are intentionally randomized.<\/p>\n<p class=\"wp-block-paragraph\">Dubey said that shift is becoming essential. \u201cThe main takeaway for me is that a file being signed by Microsoft does not make the activity behind it legitimate,\u201d he said. \u201cThe context and sequence of actions are becoming much more important than the file hash alone.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. \u201cOnce executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,\u201d Microsoft security researchers wrote in a blog post. The campaign, tracked by Microsoft Defender Experts, has impacted organizations&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16670\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16670","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16670"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16670\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}