Counterfeit Software Sites Spreading Malware Globally
A sophisticated malware campaign has been detected by Microsoft, targeting users who attempt to download popular software from counterfeit websites. The campaign, which has compromised multiple organizations and industries, primarily affects China-based operations of multinational companies and Chinese-speaking users.
The attackers use spoofed vendor download pages that clone the branding and layout of legitimate sites, making it difficult for users to distinguish between genuine and fake websites. Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure.
Microsoft has assessed with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, ) fake software campaign but has not attributed it to a nation-state actor. The company urges organizations to prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.
The attackers have used various tactics, including server-side payload regeneration and randomized executable paths, making detection challenging. However, Microsoft has detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption.