Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

“The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft said.

The installers, once launched, deploy malware that’s capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.

The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (aka WinOS 4.0).

The websites observed as part of the campaign are hosted on the .com.cn and .hl.cn infrastructure and use Chinese-language lure content to trigger the download of a ZIP archive from “gehie246[.]com.” Some of the counterfeit websites are listed below –

  • app-microsoft-edge[.]com[.]cn
  • baidu-pan[.]com[.]cn
  • calibre-ebook[.]com[.]cn
  • cn-drawio[.]com[.]cn
  • gw-sogou[.]com[.]cn
  • kaspersky-lab[.]hl[.]cn
  • mindmoster[.]com[.]cn
  • ocam-pc[.]com[.]cn
  • pc-razerzone[.]com[.]cn
  • sejda[.]hl[.]cn
  • steelseries-cn[.]com[.]cn
  • translate-youdao[.]hl[.]cn
  • zh-diskgenius[.]com[.]cn

The web pages are high-fidelity clones of the legitimate vendor’s site and feature a prominent download call-to-action. Tellingly, the archive downloaded from the site maintains the same file name while its hash changes on every download, indicating that the payload is generated server-side on the fly for every request.

Opening the archive leads to a wrapper installer (e.g., “a_instapp83353001.exe” or “ainst8663586104.exe”), which, upon execution, launches the first stage payload. Separately, Microsoft said it observed a second execution vector that makes use of the trusted Windows Installer service (“msiexec.exe”) to launch a randomized executable, mirroring the same masquerade pattern as the wrapper chain.

Regardless of the method used, persistence is achieved through scheduled tasks that imitate routine IT or productivity jobs. The malware is also responsible for creating a short-lived scheduled task that runs as SYSTEM and configures Microsoft Defender exclusions via PowerShell, deletes volume shadow copies, and ensures payload directories cannot be removed by standard users by modifying their discretionary access control lists (DACLs) using icacls.

In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update dynamic-link libraries (DLLs), and deleting the SoftwareDistribution cache.

Once all these steps are carried out, the malware establishes command-and-control (C2) over application-layer protocols on non-standard ports like 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains associated with the activity are “iualef[.]net” and “oijfwe[.]net.”

It’s unclear what the end goal of the campaign is, as Microsoft said Defender detected and initiated automated containment procedures through attack disruption to limit the attack’s impact further.

The disclosure comes merely days after Kaspersky detailed a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, while using it to initiate a DLL sideloading chain responsible for delivering ValleyRAT.

“The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user,” Kaspersky said. “In this case, however, the attackers use it to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL.”

The backdoor, besides taking steps to protect its process and prevent it from being terminated, captures keystrokes and clipboard contents, and saves the contents to a file on disk. It also periodically scans for active windows belonging to applications that could be used to analyze processes or traffic.

ValleyRAT is a sophisticated implant with a wide range of features that allows it to collect system information, reboot/shut down the computer, take screenshots, wipe logs, update C2 addresses, download additional DLL or shellcode modules, and send keylogger logs along with clipboard data.

“The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection,” Kaspersky said. “Motivated by both cyber espionage and financial gain, Silver Fox targets organizations across multiple countries.”

According to a report published by Expel last month, the use of ValleyRAT has also been attributed to a sub-group within GoldenEyeDog known as CuboidalCanine, which is assessed to have moved away from Gh0st RAT “at some point.” CuboidalCanine, per the cybersecurity company, targets the gambling industry and uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls.

“This malware isn’t unique to any actor, but has been known to be used by GoldenEyeDog,” security researcher Aaron Walton said. “Due to the source code being public, attribution of this malware to any actor relies on factors other than the malware family itself.”

In June 2026, Chinese authorities took action against a series of cybercrime cases distributing a new variant of the Silver Fox trojan, state media outlet China Daily reported.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.