Microsoft is tracking an active campaign that steers victims to cloned download pages and drops installers that cripple Windows Update and weaken Defender before establishing covert access. The company’s Defender Experts assess with moderate confidence that the activity matches the Chinese-language cluster known as Silver Fox, also called Yinhu.
The fake pages impersonate everything from Microsoft Edge to Kaspersky, Razer, Baidu Netdisk, draw.io, and Sejda PDF. Hosted on .com.cn and .hl.cn look-alike domains, they deliver a ZIP archive whose file name stays constant while the hash changes on every download, a sign that payloads are generated per request to defeat file-based blocking.
Running the archive launches a wrapper installer, and Microsoft also saw the Windows Installer service abused to execute a randomized binary. To stay resident, the malware registers scheduled tasks that mimic mundane IT maintenance. A short-lived SYSTEM task then sets Defender exclusions through PowerShell, deletes volume shadow copies, and locks payload folders with icacls. The malware additionally stops four Windows Update services, renames update DLLs, and clears the SoftwareDistribution cache, with command and control on non-standard ports.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, concentrated among Chinese-speaking users and China-based operations of multinational firms. Microsoft says automated containment limited impact for Defender customers.
