Silver Fox Hackers Use Fake Software Installers to Compromise Windows
A new campaign has been linked to the Silver Fox hacking group, where fake software installers are being used to disable Microsoft Defender and compromise Windows systems.
The hackers have created convincing download pages that mimic well-known software brands, such as Razer, Microsoft Edge, Kaspersky, and Sejda PDF. These pages offer a seemingly legitimate file for download, but the archive's contents and hash change with each request, making it difficult to block through simple filename blocking.
Once downloaded, the archive launches a wrapper that places an executable in a randomly named directory. The malware then creates scheduled tasks with harmless-sounding names, which restarts code every 60 seconds to maintain persistence.
The attackers also use PowerShell to exclude folders from Microsoft Defender's scan, write a malicious code-integrity policy, and may inject code into another program, reducing the chance that security tools inspect the files involved. The campaign has affected various industries, including healthcare, manufacturing, gaming, technology, logistics, government, and education.