Silver Fox Malware Campaign Targets Users with Fake Software Installers
A new malware campaign has been targeting users in China and other countries by distributing fake software installers. The attackers have set up bogus websites that impersonate trusted vendors, such as Microsoft, to trick users into downloading malicious files.
Once launched, the installers deploy malware that can set up persistence, weaken security protections, and communicate with attacker-controlled infrastructure. The malware also disables Windows Update and configures Microsoft Defender exclusions.
The campaign has affected multiple organizations across various industries, including healthcare, manufacturing, gaming, technology, logistics, government, and education. The attackers are suspected to be part of a Chinese threat cluster known as Silver Fox, which has been linked to the distribution of Gh0st RAT and ValleyRAT malware.