Silver Fox Hackers Spoof Major Tech Brands with Malicious Download Pages
Cybercriminals are spoofing popular technology and software companies to infect their targets with backdoors, according to Microsoft. The company discovered an ongoing campaign by Chinese hackers, known as Silver Fox or Yinhu, who create fraudulent download pages for well-known brands like Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, and MindMaster.
The backdoor implant allows attackers to maintain access and send/receive messages. Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling update-related services.
Microsoft urges organizations to enforce tamper protection, which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. It also suggests defenders hunt for 'behavior, not file names', set up alerts for tamper sequences, and treat look-alike download archives as malicious in web and mail flow.