As cited
Copy frozen at (site build).
threat intel
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Defender Experts is tracking an active malware campaign that distributes counterfeit software installers through spoofed vendor download sites impersonating brands like Razer, Microsoft Edge, and Kaspersky. The malware establishes persistence through disguised scheduled tasks, disables security protections, and communicates with attacker-controlled infrastructure, with victims primarily in China-based operations and Chinese-speaking regions across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign employs dynamic payload regeneration, process injection, and defense evasion techniques including Microsoft Defender exclusions and Windows Update neutralization.
Why it matters: Organizations in or serving China-based operations and those with Chinese-speaking users face immediate risk from counterfeit software downloads; practitioners should enable Tamper Protection, block malicious download archives by name and domain patterns, and hunt for the distinctive randomized execution paths and scheduled task behaviors that characterize this campaign.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Defender Experts is tracking an active malware campaign that distributes counterfeit software installers through spoofed vendor download sites impersonating brands like Razer, Microsoft Edge, and Kaspersky. The malware establishes persistence through disguised scheduled tasks, disables security protections, and communicates with attacker-controlled infrastructure, with victims primarily in China-based operations and Chinese-speaking regions across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign employs dynamic payload regeneration, process injection, and defense evasion techniques including Microsoft Defender exclusions and Windows Update neutralization.
Why it matters: Organizations in or serving China-based operations and those with Chinese-speaking users face immediate risk from counterfeit software downloads; practitioners should enable Tamper Protection, block malicious download archives by name and domain patterns, and hunt for the distinctive randomized execution paths and scheduled task behaviors that characterize this campaign.
- Source published
- First seen by Cybersecurity Tracker