Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to distribute dynamically generated malicious installers. The campaign, attributed with moderate confidence to Silver Fox (Yinhu), targets Chinese-speaking users and China-based operations of multinational organizations. The attack chain involves dropping randomized payloads, establishing persistence via disguised scheduled tasks, escalating privileges using SYSTEM scheduled tasks, and employing defense evasion techniques such as adding Defender exclusions, deleting shadow copies, and disabling Windows Update.
Counterfeit Software
1 post
Counterfeit installers to system compromise: Tracking a deceptive software download campaign | Microsoft Security Blog