Silver Fox-Linked Hackers Are Using Fake Software Installers to Blind Windows Defender
Want more insights like this?
A hacking group linked to Silver Fox (also known as Yinhu) is running a campaign that tricks users into downloading fake installers disguised as Razer, Microsoft Edge, Kaspersky, and other trusted tools. The sites look legitimate — until you open the ZIP file. Microsoft says the payload changes on every download, so hashes shift while filenames stay put.
Once installed, the malware doesn't switch Microsoft Defender off — it uses short-lived SYSTEM scheduled tasks to write sweeping scan exclusions, then deletes the tasks to cover its tracks. It also deletes shadow copies, stops Windows Update, and sets up recurring tasks that restart malicious code every 60 seconds.
Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, most of them the China-based operations of multinational organizations, or Chinese-speaking users. Microsoft assesses with moderate confidence that the activity is consistent with the reported Silver Fox campaign, and has stopped short of attributing it to a nation-state.
Turn on Tamper Protection — Microsoft says it blocks Defender exclusion and registry writes even when the payload is running as SYSTEM, which is exactly what this campaign depends on. And always download software directly from official publishers.
Source: Cybersecurity News