Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fox-Linked Hackers Disable Microsoft Defender With Fake Software
September 2, 2026
Microsoft Teams Phishing Campaign Lets Attackers Remotely Control PCs
September 2, 2026
Critical HPE Fabric Composer Flaws Allow Remote Code Execution
September 2, 2026
Home/CyberSecurity News/Fox-Linked Hackers Disable Microsoft Defender With Fake Software
CyberSecurity News

Fox-Linked Hackers Disable Microsoft Defender With Fake Software

Key Takeaways A threat group known as Silver Fox (or Yinhu) is actively distributing malicious software installers designed to compromise Windows systems. The attackers use convincing fake download...

Emy Elsamnoudy
Emy Elsamnoudy
September 2, 2026 4 Min Read
2 0

Key Takeaways

  • A threat group known as Silver Fox (or Yinhu) is actively distributing malicious software installers designed to compromise Windows systems.
  • The attackers use convincing fake download pages for popular software like Razer, Microsoft Edge, and Kaspersky to trick users.
  • Once executed, the malware disables Microsoft Defender, establishes persistence through scheduled tasks, and attempts to hinder system recovery mechanisms.
  • Victims primarily include organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, with a notable focus on Chinese-speaking users or China-based operations.
  • There is no direct patch for this social engineering attack; vigilance against suspicious downloads and robust endpoint security configurations are crucial for defense.

Silver Fox Leverages Counterfeit Software to Cripple Windows Defenses

A sophisticated cyber campaign, attributed to the threat group known as Silver Fox or Yinhu, is actively exploiting trust in legitimate software downloads to infiltrate Windows environments. These attackers deploy meticulously crafted fake software installers that not only gain initial access but also systematically dismantle native security protections, including Microsoft Defender.

Table Of Content

  • Key Takeaways
  • Silver Fox Leverages Counterfeit Software to Cripple Windows Defenses
  • The Deceptive Attack Chain
  • Recovery and Detection Priorities

The campaign employs highly deceptive download pages that mimic popular software brands, presenting users with what appears to be a legitimate file. This tactic has enabled the attackers to compromise organizations across diverse sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. While a significant portion of the identified victims have ties to China-based operations or Chinese-speaking users, the broad appeal of the lures means any organization could be targeted.

Microsoft analysts have, with moderate confidence, linked this activity to the publicly documented Silver Fox fake-software campaign. Though Microsoft has not officially attributed the campaign to a nation-state actor, its analysis indicates that the malware is designed to establish a persistent foothold, degrade system defenses, and communicate with attacker-controlled infrastructure. As Microsoft said in a report, this highlights a critical vulnerability: a seemingly routine download from a spoofed vendor site can escalate into a full endpoint compromise.

The Deceptive Attack Chain

The infiltration process begins with users navigating to counterfeit websites that impersonate well-known software providers such as Razer, Microsoft Edge, Kaspersky, and Sejda PDF. Upon clicking “Download now,” the site delivers a ZIP archive. Crucially, the filename of this archive remains consistent, but its contents and cryptographic hash are unique with each download request. This “per-download rebuilding” strategy significantly complicates detection efforts that rely on simple file-name or hash-based blocking, as demonstrated by one instance where two distinct copies of the same archive were observed within approximately 69 seconds.

This method mirrors other fake installer malware campaigns, where the familiarity of trusted branding lulls users into a false sense of security, making the initial malicious click appear innocuous. The contents of these archives are detailed in a comprehensive report on the Silver Fox campaign, which can be reviewed for further technical indicators.

Once opened, the malicious archive initiates a wrapper that extracts an executable into a randomly named directory within common system locations like UsersPublic, ProgramData, or Program Files (x86). An alternative execution path involves msiexec.exe, the Windows Installer, allowing the malicious code to run under the guise of a legitimate Windows component while the user perceives a normal software installation. This technique is outlined in a detailed analysis of the Silver Fox group’s tactics.

The payloads then proceed to create scheduled tasks with benign-sounding names, such as “Deadline Mission Target” and “Hierarchy Tools Smooth Inventory.” These tasks are configured to restart the malicious code approximately every 60 seconds, illustrating why Windows scheduled task abuse remains a favored persistence technique for adversaries.

A more critical step in the attack involves the malware creating a temporary task with SYSTEM privileges—the highest local privilege in Windows—to implement extensive exclusions for Microsoft Defender. Furthermore, the attackers utilize PowerShell to exclude specific folders, deploy a malicious code-integrity policy, and may inject code into other legitimate programs to evade detection by security tools. Details on these defense evasion techniques are available in the report.

Recovery and Detection Priorities

The Silver Fox campaign extends beyond simply bypassing antivirus measures. Researchers have observed commands designed to delete volume shadow copies, significantly hindering system recovery efforts, and actions to disable or halt Windows Update services. The attackers also reinforce the security of their directories against removal and establish communication with command-and-control (C2) servers over non-standard ports before initiating further malicious activities.

Microsoft has reported instances of automated containment alongside manual “hands-on-keyboard” activity and attempts at lateral movement via Server Message Block (SMB). Even when a device is contained, security teams must undertake a thorough incident response to fully eliminate scheduled tasks and other persistent mechanisms left behind by the attackers.

This incident underscores the critical importance of restricting software downloads to official vendor sources and treating any brand-lookalike pages, particularly those offering unexpected ZIP installers, with extreme suspicion. Network and email security controls should be configured to block known delivery routes. Security teams should proactively monitor download referrers, new executables appearing in writable folders, unusual msiexec activity, and newly created scheduled tasks for signs of compromise.

Administrators are advised to keep tamper protection and network protection features enabled on their endpoints. Furthermore, they should configure alerts for changes to Defender exclusions, attempts to delete shadow copies, and any efforts to disable update services. This situation echoes previous attacks, such as <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/f95dadc1-c842-433d-a883-e01779165e9b/Silver-Fox-Linked-Hackers-Use-Fake-Software-Installers-to-Disable-Microsoft-Defender-and-Compromise-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE2G45J362&Signature=HSQ7uIWfugEgkPZpQ7OI8T0zW47w%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEPn%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDSrQWxIwusUOMU8mP1UhSXHCR4LM4bjhxWuFIdGKgNqAiAP935grKBOFy6Y09NNtxlynqKVEtRvc0NzEi5QgIsiJyr8BAjB%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM5miF1A7tyEg66AXAKtAEUUKpGNzJhA9PKXYPUtDrn5%2B1tsqsfoA%2F0VBIF1dXoYQc32s5NeFSjx9u%2FBPra%2FwbLNwoDtujtyHNC0Z4akMuAnPI%2F3lGDHBdSTHhUsNfO3Rg7PhasgTAi0qRHyJenQx%2FxuUUfOvaz9tBHe2B5M6Gk0LBJGUU8lI6yJwMcvRp5kO8UxiWfR3FWB7JYp1cneLdvr3mbC7DZ%2BzgFSSDjzw5dlB5G18Kd61UjKazxLDjAwgY1wrdP97rZnLT6SITN68OlyrqOFX5yTxmziXW3ABXYKSOpkQlyMCGQ5tf1n2gNPlfPxBjtga%2B8M9CLa%2FEDim87OnTzlcswGIgUaf7%2BWl

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Microsoft Teams Phishing Campaign Lets Attackers Remotely Control PCs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hugging Face Vulnerability Exposes Users to Malicious AI Model Code Execution
September 2, 2026
Google Chrome Update Patches 2 Critical Use-After-Free Vulnerabilities
September 2, 2026
Anthropic Debuts Claude 3.5 Sonnet for Advanced AI Capabilities
September 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us