Silver Fox Hackers Spoof Popular Tech Brands to Spread Malware
Cybercriminals have been spoofing popular tech brands to infect their targets with backdoors. Microsoft researchers discovered an ongoing campaign where Chinese hackers, allegedly from group Silver Fox (also known as Yinhu), created fake download pages for companies like Razer, Kaspersky, and NetEase.
The malicious software allows attackers to maintain access and send/receive messages. Once installed, the backdoor creates scheduled tasks for persistence, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating a large exclusion folder and disabling update-related services.
Victims are primarily Chinese organizations in various industries, including healthcare, manufacturing, gaming, technology, logistics, government, and higher education. To defend against this threat, Microsoft advises enforcing tamper protection, which blocks exclusion and registry writes to Defender even when the payload runs as SYSTEM.