
Cybersecurity researchers have uncovered an active malware campaign that uses fake software-download websites to impersonate trusted vendors and distribute malicious installers.
According to Microsoft, the campaign has targeted users searching for popular software and has led to compromises across multiple organisations and industries. The activity has primarily affected China-based operations of multinational organisations and Chinese-speaking users.
The campaign has reached victims in healthcare, manufacturing, gaming, technology, logistics, government and education. Microsoft assessed with moderate confidence that the activity is linked to the Chinese threat cluster Silver Fox, also known as Yinhu, which has previously used fake vendor download pages to distribute malware including Gh0st RAT and ValleyRAT.
The counterfeit websites closely replicate legitimate vendor pages and use prominent download prompts to trick users. The observed sites use Chinese-language content and are hosted on .com.cn and .hl.cn infrastructure.
Among the impersonated brands and services are Microsoft Edge, Baidu Pan, Calibre, draw.io, Sogou, Kaspersky, MindMaster, OCAM, Razer, Sejda, SteelSeries, Youdao and DiskGenius.
The downloaded ZIP archive retains the same filename, but its hash changes with every download, suggesting that the malicious payload is generated on the server for each request.
Once opened, the archive launches a wrapper installer that executes the first-stage payload. Microsoft also observed another method involving the legitimate Windows Installer service, msiexec.exe, which launches a randomized executable.
The malware establishes persistence through scheduled tasks disguised as routine IT or productivity jobs. It can also create a temporary SYSTEM-level task to configure Microsoft Defender exclusions through PowerShell, delete volume shadow copies and modify file permissions using icacls.
The malware further interferes with Windows Update by stopping and disabling services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc. It also renames update DLLs and deletes the SoftwareDistribution cache.
After compromising a system, the malware establishes command-and-control communications through non-standard ports including 5090, 7031, 7032, 7088–7090, 8050, 28290 and 28300. Microsoft identified the C2 domains iualef[.]net and oijfwe[.]net.
The campaign’s ultimate objective remains unclear. Microsoft said Defender detected the activity and initiated automated containment through attack disruption.
The disclosure follows a separate Kaspersky report involving a modified version of QN Wallpaper that uses DLL sideloading to deliver ValleyRAT. The backdoor can capture keystrokes and clipboard data, collect system information, take screenshots, wipe logs and download additional malicious modules.
Recent research has also linked ValleyRAT activity to the CuboidalCanine subgroup associated with GoldenEyeDog, although researchers noted that the malware itself is not unique to a single threat actor.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.

