Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Botnet Burns AI Credits, Steals Data
September 29, 2026
New 7-Zip Installer Malware Evades Detection
September 29, 2026
Attackers Exploit Ethereum Blockchain for Covert Malware Communications
September 29, 2026
Home/Threats/SilverFox Hackers Use Fake Software Sites to Distribute Malware
Threats

SilverFox Hackers Use Fake Software Sites to Distribute Malware

Key Takeaways The SilverFox threat actor group is actively distributing malware through deceptive software download websites. These campaigns primarily target Windows users, with a notable focus on...

Jennifer sherman
Jennifer sherman
September 29, 2026 5 Min Read
2 0

Key Takeaways

  • The SilverFox threat actor group is actively distributing malware through deceptive software download websites.
  • These campaigns primarily target Windows users, with a notable focus on Chinese-speaking populations across various industries.
  • Attackers leverage fake installer packages that mimic legitimate software, establishing persistence and attempting to disable security features.
  • Two distinct infection chains have been identified: one via counterfeit websites and another through malicious WhatsApp attachments.
  • Users should exercise extreme caution when downloading software and verify sources rigorously to avoid compromise.

A sophisticated malware campaign linked to the SilverFox group, also known as Yinhu, is leveraging counterfeit software download sites to infect Windows systems. These malicious pages meticulously replicate the appearance of legitimate vendor sites, distributing installers that grant attackers persistent access to compromised machines.

Table Of Content

  • Key Takeaways
  • SilverFox Hackers Built Fake Software Sites
  • Persistence And Detection Clues
  • What You Should Do

Microsoft researchers have documented successful intrusions across multiple sectors, predominantly impacting Chinese-speaking users. The attackers exploit a common user behavior: searching for an application, recognizing familiar branding, and then clicking to download without sufficient verification. Beyond these deceptive websites, SilverFox has also been observed utilizing malicious messages and attachments as part of their broader distribution tactics.

In a separate but related discovery, analysts at Pelagos Intel uncovered an infection chain initiated by a finance-themed WhatsApp message sent to a recipient in Malaysia. This message contained an attachment with a digitally signed program alongside an unsigned library. While this finding highlights another facet of SilverFox’s operations, it is important to note that this WhatsApp-based attack has not been definitively linked to the counterfeit website campaign.

Microsoft has assessed, with moderate confidence, that the fake-installer campaign aligns with the SilverFox threat actor’s known methodologies. However, the company has not attributed this operation to any specific nation-state actor.

Pelagos Intel said in a report shared with Cyber Security News (CSN) that the files analyzed in their separate investigation established system persistence and made repeated attempts to connect with an external command-and-control server.

SilverFox Hackers Built Fake Software Sites

The fraudulent download pages meticulously mimic the interfaces of authentic software providers, offering what appear to be legitimate installers for popular browsers, security tools, and common utilities. Microsoft’s investigation into these SilverFox fake installers revealed how convincing branding effectively conceals a dangerous infection process.

Microsoft tracked users from a deceptive page to a download server hosting a ZIP archive. The research indicates that two archives, despite sharing identical names and being downloaded approximately 69 seconds apart, contained distinct content. This suggests that the archive could be dynamically rebuilt for each download request, even as its filename and download URL remained constant. This method complicates detection, as a single archive hash becomes an unreliable indicator for identifying all malicious copies. However, Microsoft has not found evidence that these websites specifically identify and evade security researchers.

Upon execution, the downloaded archive deploys a wrapper that injects malicious code into a randomly named Windows directory. Another observed infection vector involves the Windows Installer, a native system component. Consequently, users expecting a straightforward software installation may overlook the clandestine execution of additional programs in the background, especially given the highly convincing nature of the fake download pages.

This tactic is not new for SilverFox; a previous infection was linked to a fake security software download, although those were distinct operations. These incidents underscore the critical need for heightened scrutiny of recognizable branding and seemingly ordinary installers, particularly when the download source cannot be independently verified.

Persistence And Detection Clues

Microsoft’s analysis revealed that the later stages of the malware deployment involve creating scheduled tasks to ensure the malicious programs restart automatically. The malware also briefly executes a task with elevated system privileges to modify security exclusions. Furthermore, the malware attempts to disable Windows Update, remove system recovery points, and establish communication with attacker-controlled infrastructure. These modifications significantly hinder both the discovery and remediation efforts once the initial installer has completed its operation.

In the WhatsApp case investigated by Pelagos Intel, the technical approach differed. A legitimately signed launcher invoked functions within an unsigned library, which masqueraded as a standard Windows desktop component. This library was responsible for decoding obfuscated data and transferring the transformed content into executable memory. Subsequently, these files were duplicated into a user profile, with a corresponding startup registry entry configured to ensure their automatic execution upon system boot.

During testing, Pelagos recorded 96 connection attempts occurring approximately every three seconds. They also observed a successful decryption operation whose output length precisely matched a transformation identified during code analysis. These findings strongly suggest a configured, persistent loader, although the report does not establish a direct link between this specific chain and Microsoft’s fake-site campaign.

Previous reports on malware being loaded by trusted software highlight why a valid digital signature on one file does not guarantee the integrity of all associated components. Similarly, SilverFox’s use of tax-themed lures demonstrates that a seemingly credible document or message can initiate a separate infection. These instances provide valuable context for understanding the threat actor’s tactics but do not confirm shared infrastructure, a crucial distinction when security teams compare samples and incident reports.

For the counterfeit-site campaign, Microsoft advises users to download software exclusively from verified official sources, remain vigilant for unexpected archive downloads, and configure alerts for suspicious scheduled tasks or unauthorized changes to security settings. In the context of the WhatsApp infection chain, Pelagos highlights specific indicators such as the unusual startup registry entry, the pair of staged files, and consistent outbound connection attempts as key investigative leads. Security teams must ascertain which infection chain they are investigating before applying the appropriate indicators of compromise.

What You Should Do

  • Download Software from Official Sources Only: Always obtain software directly from the vendor’s official website or trusted app stores. Avoid third-party download sites, even if they appear legitimate.
  • Verify Digital Signatures: Before running any executable, check its digital signature to confirm the publisher’s identity. Be wary of unsigned executables or those with unexpected signers.
  • Monitor for Suspicious Activity: Implement endpoint detection and response (EDR) solutions to monitor for unusual scheduled tasks, unexpected file creations in system directories (e.g., %APPDATA%MicrosoftUpdate), or attempts to modify security settings or disable Windows Update.
  • Educate Users on Phishing and Social Engineering: Train users to recognize and report suspicious emails, messages (e.g., WhatsApp), and attachments, especially those with financial themes or urgent calls to action.
  • Review Startup Programs and Registry Entries: Regularly inspect startup programs and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) for unknown or suspicious entries.
  • Analyze Network Traffic: Monitor outbound network connections for unusual activity, particularly repeated attempts to connect to unfamiliar IP addresses or domains (e.g., 134.122.155.135:443).
  • Maintain Backups: Regularly back up critical data to an isolated location to facilitate recovery in the event of a successful compromise.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 9F2CAEDA208C9D729B44F31C32B5E1EEEF18D84D6E36B04AFE15D894D3809672 Delivered ZIP archive
SHA-256 E2BF8B7CD396EE950A5B6911EA098C2E49D4ED002A6C04D5D660CCD4F7D66BAA IMG disk image
SHA-256 F712C2A8B4ABF2E299A2B480020333DEB0F43364E9686CDA78B1243C62E4830D Signed executable
SHA-256 C1E184615241FE69DB3BF4093A22C7C0BF5D6072D2F51E558142B844E871084F Unsigned companion DLL
Network endpoint 134.122.155.135:443 Repeated outbound connection attempts
File name PDF_C2841_20260911100446.zip WhatsApp attachment
File name PDF_C2089_20260911100446.exe Signed executable
File name active_desktop_render_x64.dll Companion DLL
Staging path %APPDATA%MicrosoftUpdate Directory used to stage both files
Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun Startup persistence location
Registry value MicrosoftUpdate Observed startup value name
Signer Guangzhou Kugou Technology Co., Ltd. Signer identified for the executable
Certificate thumbprint 757BDD02CBA91CA59C46E2098A5479C1ABC1FDBE Certificate identifier
PDB path D:buildbotbuild1desktop_screenbuildbinactive_desktop_launcher_x64.pdb Build-path artifact
Configuration marker @@RAPID_CFG_START@@ Marker found in decrypted data
File metadata active_desktop_launcher.exe Executable identity in version resources
File metadata dwmapi.dll Original filename claimed in DLL metadata
Hunting string ReleaseFromExplorer Static-analysis clustering term
Hunting string _ipcfr_wqkqzk Static-analysis clustering term

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

OpenAI Halts GPT-6.1 Astra Rollout Due to Security Concerns

Next Post

Attackers Exploit Ethereum Blockchain for Covert Malware Communications

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws
September 29, 2026
GPT-6 Astra AI Agent Attempts Supply Chain Attacks
September 29, 2026
Threat Actors Weaponize Custom GPTs to Deliver Malware
September 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us