Microsoft uncovers malware campaign using counterfeit installers to disable security defenses
It looks like software, but it smells like a RAT.

Image by Photo by Gary Hershorn via Getty Images
- Microsoft found fake software sites impersonating brands such as Edge, Kaspersky, Razer, and draw.io.
- Victims install malware that disables Windows Update and changes Microsoft Defender settings.
- The campaign mainly affects China-based multinational organizations and Chinese-speaking users.
- Microsoft links the campaign to Silver Fox with moderate confidence and urges downloads from trusted sources.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Microsoft security experts have been tracking an active malware campaign that tries to trick gullible people into downloading fake software from websites that impersonate trusted vendors and brands.
Microsoft has found several malicious domains cloning a real brand’s products, including Microsoft Edge, Kaspersky, Razer, and draw.io.
Instead of downloading legitimate drivers or software, victims are installing malware on their devices that gives attackers access to their systems.
Once installed, the malware disables Windows Update, changes Microsoft Defender settings to bypass security measures, and attempts to gain SYSTEM privileges.
Via the infected device, the attackers try to move laterally to other systems on the network and communicate with an attacker-controlled command-and-control infrastructure.
Microsoft says it has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors, primarily affecting China-based multinational organizations and Chinese-speaking users.
“With moderate confidence,” Microsoft believes this fake software campaign can be attributed to Silver Fox, a cybercriminal group known for such attacks.
Typically, Silver Fox creates a fake website that impersonates a trusted software brand. Potential victims usually end up at these sites through malicious advertisements on search engine results pages or through SEO poisoning.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
They download what appears to be legitimate software, but in reality is a remote access trojan (RAT) or other malware in disguise.
Once the malicious software is installed, the attackers will have control over the compromised device and can move laterally through a corporate network in search of sensitive data.
Microsoft doesn’t say what the attackers’ goal is. The Redmond-based tech company recommends only downloading from trusted sources and closely monitoring networks for suspicious patterns and activities.