SilverFox Hackers Use Fake Software Sites to Distribute Malware
Key Takeaways The SilverFox threat actor group is actively distributing malware through deceptive software download websites. These campaigns primarily target Windows users, with a notable focus on...
Key Takeaways
- The SilverFox threat actor group is actively distributing malware through deceptive software download websites.
- These campaigns primarily target Windows users, with a notable focus on Chinese-speaking populations across various industries.
- Attackers leverage fake installer packages that mimic legitimate software, establishing persistence and attempting to disable security features.
- Two distinct infection chains have been identified: one via counterfeit websites and another through malicious WhatsApp attachments.
- Users should exercise extreme caution when downloading software and verify sources rigorously to avoid compromise.
A sophisticated malware campaign linked to the SilverFox group, also known as Yinhu, is leveraging counterfeit software download sites to infect Windows systems. These malicious pages meticulously replicate the appearance of legitimate vendor sites, distributing installers that grant attackers persistent access to compromised machines.
Table Of Content
Microsoft researchers have documented successful intrusions across multiple sectors, predominantly impacting Chinese-speaking users. The attackers exploit a common user behavior: searching for an application, recognizing familiar branding, and then clicking to download without sufficient verification. Beyond these deceptive websites, SilverFox has also been observed utilizing malicious messages and attachments as part of their broader distribution tactics.
In a separate but related discovery, analysts at Pelagos Intel uncovered an infection chain initiated by a finance-themed WhatsApp message sent to a recipient in Malaysia. This message contained an attachment with a digitally signed program alongside an unsigned library. While this finding highlights another facet of SilverFox’s operations, it is important to note that this WhatsApp-based attack has not been definitively linked to the counterfeit website campaign.
Microsoft has assessed, with moderate confidence, that the fake-installer campaign aligns with the SilverFox threat actor’s known methodologies. However, the company has not attributed this operation to any specific nation-state actor.
Pelagos Intel said in a report shared with Cyber Security News (CSN) that the files analyzed in their separate investigation established system persistence and made repeated attempts to connect with an external command-and-control server.
SilverFox Hackers Built Fake Software Sites
The fraudulent download pages meticulously mimic the interfaces of authentic software providers, offering what appear to be legitimate installers for popular browsers, security tools, and common utilities. Microsoft’s investigation into these SilverFox fake installers revealed how convincing branding effectively conceals a dangerous infection process.
Microsoft tracked users from a deceptive page to a download server hosting a ZIP archive. The research indicates that two archives, despite sharing identical names and being downloaded approximately 69 seconds apart, contained distinct content. This suggests that the archive could be dynamically rebuilt for each download request, even as its filename and download URL remained constant. This method complicates detection, as a single archive hash becomes an unreliable indicator for identifying all malicious copies. However, Microsoft has not found evidence that these websites specifically identify and evade security researchers.
Upon execution, the downloaded archive deploys a wrapper that injects malicious code into a randomly named Windows directory. Another observed infection vector involves the Windows Installer, a native system component. Consequently, users expecting a straightforward software installation may overlook the clandestine execution of additional programs in the background, especially given the highly convincing nature of the fake download pages.
This tactic is not new for SilverFox; a previous infection was linked to a fake security software download, although those were distinct operations. These incidents underscore the critical need for heightened scrutiny of recognizable branding and seemingly ordinary installers, particularly when the download source cannot be independently verified.
Persistence And Detection Clues
Microsoft’s analysis revealed that the later stages of the malware deployment involve creating scheduled tasks to ensure the malicious programs restart automatically. The malware also briefly executes a task with elevated system privileges to modify security exclusions. Furthermore, the malware attempts to disable Windows Update, remove system recovery points, and establish communication with attacker-controlled infrastructure. These modifications significantly hinder both the discovery and remediation efforts once the initial installer has completed its operation.
In the WhatsApp case investigated by Pelagos Intel, the technical approach differed. A legitimately signed launcher invoked functions within an unsigned library, which masqueraded as a standard Windows desktop component. This library was responsible for decoding obfuscated data and transferring the transformed content into executable memory. Subsequently, these files were duplicated into a user profile, with a corresponding startup registry entry configured to ensure their automatic execution upon system boot.
During testing, Pelagos recorded 96 connection attempts occurring approximately every three seconds. They also observed a successful decryption operation whose output length precisely matched a transformation identified during code analysis. These findings strongly suggest a configured, persistent loader, although the report does not establish a direct link between this specific chain and Microsoft’s fake-site campaign.
Previous reports on malware being loaded by trusted software highlight why a valid digital signature on one file does not guarantee the integrity of all associated components. Similarly, SilverFox’s use of tax-themed lures demonstrates that a seemingly credible document or message can initiate a separate infection. These instances provide valuable context for understanding the threat actor’s tactics but do not confirm shared infrastructure, a crucial distinction when security teams compare samples and incident reports.
For the counterfeit-site campaign, Microsoft advises users to download software exclusively from verified official sources, remain vigilant for unexpected archive downloads, and configure alerts for suspicious scheduled tasks or unauthorized changes to security settings. In the context of the WhatsApp infection chain, Pelagos highlights specific indicators such as the unusual startup registry entry, the pair of staged files, and consistent outbound connection attempts as key investigative leads. Security teams must ascertain which infection chain they are investigating before applying the appropriate indicators of compromise.
What You Should Do
- Download Software from Official Sources Only: Always obtain software directly from the vendor’s official website or trusted app stores. Avoid third-party download sites, even if they appear legitimate.
- Verify Digital Signatures: Before running any executable, check its digital signature to confirm the publisher’s identity. Be wary of unsigned executables or those with unexpected signers.
- Monitor for Suspicious Activity: Implement endpoint detection and response (EDR) solutions to monitor for unusual scheduled tasks, unexpected file creations in system directories (e.g.,
%APPDATA%MicrosoftUpdate), or attempts to modify security settings or disable Windows Update. - Educate Users on Phishing and Social Engineering: Train users to recognize and report suspicious emails, messages (e.g., WhatsApp), and attachments, especially those with financial themes or urgent calls to action.
- Review Startup Programs and Registry Entries: Regularly inspect startup programs and registry run keys (e.g.,
HKCUSoftwareMicrosoftWindowsCurrentVersionRun) for unknown or suspicious entries. - Analyze Network Traffic: Monitor outbound network connections for unusual activity, particularly repeated attempts to connect to unfamiliar IP addresses or domains (e.g.,
134.122.155.135:443). - Maintain Backups: Regularly back up critical data to an isolated location to facilitate recovery in the event of a successful compromise.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 |
Delivered ZIP archive |
| SHA-256 | E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA |
IMG disk image |
| SHA-256 | F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D |
Signed executable |
| SHA-256 | C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F |
Unsigned companion DLL |
| Network endpoint | 134.122.155.135:443 |
Repeated outbound connection attempts |
| File name | PDF_C2841_20260911100446.zip |
WhatsApp attachment |
| File name | PDF_C2089_20260911100446.exe |
Signed executable |
| File name | active_desktop_render_x64.dll |
Companion DLL |
| Staging path | %APPDATA%MicrosoftUpdate |
Directory used to stage both files |
| Registry key | HKCUSoftwareMicrosoftWindowsCurrentVersionRun |
Startup persistence location |
| Registry value | MicrosoftUpdate |
Observed startup value name |
| Signer | Guangzhou Kugou Technology Co., Ltd. |
Signer identified for the executable |
| Certificate thumbprint | 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE |
Certificate identifier |
| PDB path | D:buildbotbuild1desktop_screenbuildbinactive_desktop_launcher_x64.pdb |
Build-path artifact |
| Configuration marker | @@RAPID_CFG_START@@ |
Marker found in decrypted data |
| File metadata | active_desktop_launcher.exe |
Executable identity in version resources |
| File metadata | dwmapi.dll |
Original filename claimed in DLL metadata |
| Hunting string | ReleaseFromExplorer |
Static-analysis clustering term |
| Hunting string | _ipcfr_wqkqzk |
Static-analysis clustering term |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.