Fox-Linked Hackers Disable Microsoft Defender With Fake Software
Key Takeaways A threat group known as Silver Fox (or Yinhu) is actively distributing malicious software installers designed to compromise Windows systems. The attackers use convincing fake download...
Key Takeaways
- A threat group known as Silver Fox (or Yinhu) is actively distributing malicious software installers designed to compromise Windows systems.
- The attackers use convincing fake download pages for popular software like Razer, Microsoft Edge, and Kaspersky to trick users.
- Once executed, the malware disables Microsoft Defender, establishes persistence through scheduled tasks, and attempts to hinder system recovery mechanisms.
- Victims primarily include organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, with a notable focus on Chinese-speaking users or China-based operations.
- There is no direct patch for this social engineering attack; vigilance against suspicious downloads and robust endpoint security configurations are crucial for defense.
Silver Fox Leverages Counterfeit Software to Cripple Windows Defenses
A sophisticated cyber campaign, attributed to the threat group known as Silver Fox or Yinhu, is actively exploiting trust in legitimate software downloads to infiltrate Windows environments. These attackers deploy meticulously crafted fake software installers that not only gain initial access but also systematically dismantle native security protections, including Microsoft Defender.
Table Of Content
The campaign employs highly deceptive download pages that mimic popular software brands, presenting users with what appears to be a legitimate file. This tactic has enabled the attackers to compromise organizations across diverse sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. While a significant portion of the identified victims have ties to China-based operations or Chinese-speaking users, the broad appeal of the lures means any organization could be targeted.
Microsoft analysts have, with moderate confidence, linked this activity to the publicly documented Silver Fox fake-software campaign. Though Microsoft has not officially attributed the campaign to a nation-state actor, its analysis indicates that the malware is designed to establish a persistent foothold, degrade system defenses, and communicate with attacker-controlled infrastructure. As Microsoft said in a report, this highlights a critical vulnerability: a seemingly routine download from a spoofed vendor site can escalate into a full endpoint compromise.
The Deceptive Attack Chain
The infiltration process begins with users navigating to counterfeit websites that impersonate well-known software providers such as Razer, Microsoft Edge, Kaspersky, and Sejda PDF. Upon clicking “Download now,” the site delivers a ZIP archive. Crucially, the filename of this archive remains consistent, but its contents and cryptographic hash are unique with each download request. This “per-download rebuilding” strategy significantly complicates detection efforts that rely on simple file-name or hash-based blocking, as demonstrated by one instance where two distinct copies of the same archive were observed within approximately 69 seconds.
This method mirrors other fake installer malware campaigns, where the familiarity of trusted branding lulls users into a false sense of security, making the initial malicious click appear innocuous. The contents of these archives are detailed in a comprehensive report on the Silver Fox campaign, which can be reviewed for further technical indicators.
Once opened, the malicious archive initiates a wrapper that extracts an executable into a randomly named directory within common system locations like UsersPublic, ProgramData, or Program Files (x86). An alternative execution path involves msiexec.exe, the Windows Installer, allowing the malicious code to run under the guise of a legitimate Windows component while the user perceives a normal software installation. This technique is outlined in a detailed analysis of the Silver Fox group’s tactics.
The payloads then proceed to create scheduled tasks with benign-sounding names, such as “Deadline Mission Target” and “Hierarchy Tools Smooth Inventory.” These tasks are configured to restart the malicious code approximately every 60 seconds, illustrating why Windows scheduled task abuse remains a favored persistence technique for adversaries.
A more critical step in the attack involves the malware creating a temporary task with SYSTEM privileges—the highest local privilege in Windows—to implement extensive exclusions for Microsoft Defender. Furthermore, the attackers utilize PowerShell to exclude specific folders, deploy a malicious code-integrity policy, and may inject code into other legitimate programs to evade detection by security tools. Details on these defense evasion techniques are available in the report.
Recovery and Detection Priorities
The Silver Fox campaign extends beyond simply bypassing antivirus measures. Researchers have observed commands designed to delete volume shadow copies, significantly hindering system recovery efforts, and actions to disable or halt Windows Update services. The attackers also reinforce the security of their directories against removal and establish communication with command-and-control (C2) servers over non-standard ports before initiating further malicious activities.
Microsoft has reported instances of automated containment alongside manual “hands-on-keyboard” activity and attempts at lateral movement via Server Message Block (SMB). Even when a device is contained, security teams must undertake a thorough incident response to fully eliminate scheduled tasks and other persistent mechanisms left behind by the attackers.
This incident underscores the critical importance of restricting software downloads to official vendor sources and treating any brand-lookalike pages, particularly those offering unexpected ZIP installers, with extreme suspicion. Network and email security controls should be configured to block known delivery routes. Security teams should proactively monitor download referrers, new executables appearing in writable folders, unusual msiexec activity, and newly created scheduled tasks for signs of compromise.
Administrators are advised to keep tamper protection and network protection features enabled on their endpoints. Furthermore, they should configure alerts for changes to Defender exclusions, attempts to delete shadow copies, and any efforts to disable update services. This situation echoes previous attacks, such as <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/f95dadc1-c842-433d-a883-e01779165e9b/Silver-Fox-Linked-Hackers-Use-Fake-Software-Installers-to-Disable-Microsoft-Defender-and-Compromise-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE2G45J362&Signature=HSQ7uIWfugEgkPZpQ7OI8T0zW47w%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEPn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDSrQWxIwusUOMU8mP1UhSXHCR4LM4bjhxWuFIdGKgNqAiAP935grKBOFy6Y09NNtxlynqKVEtRvc0NzEi5QgIsiJyr8BAjB%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM5miF1A7tyEg66AXAKtAEUUKpGNzJhA9PKXYPUtDrn5%2B1tsqsfoA%2F0VBIF1dXoYQc32s5NeFSjx9u%2FBPra%2FwbLNwoDtujtyHNC0Z4akMuAnPI%2F3lGDHBdSTHhUsNfO3Rg7PhasgTAi0qRHyJenQx%2FxuUUfOvaz9tBHe2B5M6Gk0LBJGUU8lI6yJwMcvRp5kO8UxiWfR3FWB7JYp1cneLdvr3mbC7DZ%2BzgFSSDjzw5dlB5G18Kd61UjKazxLDjAwgY1wrdP97rZnLT6SITN68OlyrqOFX5yTxmziXW3ABXYKSOpkQlyMCGQ5tf1n2gNPlfPxBjtga%2B8M9CLa%2FEDim87OnTzlcswGIgUaf7%2BWl
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.