CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5518

As cited

Copy frozen at (site build).

threat intel

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that distributes counterfeit software installers through spoofed vendor download sites impersonating brands like Razer, Microsoft Edge, and Kaspersky. The malware establishes persistence through disguised scheduled tasks, disables security protections, and communicates with attacker-controlled infrastructure, with victims primarily in China-based operations and Chinese-speaking regions across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign employs dynamic payload regeneration, process injection, and defense evasion techniques including Microsoft Defender exclusions and Windows Update neutralization.

Why it matters: Organizations in or serving China-based operations and those with Chinese-speaking users face immediate risk from counterfeit software downloads; practitioners should enable Tamper Protection, block malicious download archives by name and domain patterns, and hunt for the distinctive randomized execution paths and scheduled task behaviors that characterize this campaign.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that distributes counterfeit software installers through spoofed vendor download sites impersonating brands like Razer, Microsoft Edge, and Kaspersky. The malware establishes persistence through disguised scheduled tasks, disables security protections, and communicates with attacker-controlled infrastructure, with victims primarily in China-based operations and Chinese-speaking regions across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign employs dynamic payload regeneration, process injection, and defense evasion techniques including Microsoft Defender exclusions and Windows Update neutralization.

Why it matters: Organizations in or serving China-based operations and those with Chinese-speaking users face immediate risk from counterfeit software downloads; practitioners should enable Tamper Protection, block malicious download archives by name and domain patterns, and hunt for the distinctive randomized execution paths and scheduled task behaviors that characterize this campaign.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary