installers

Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
AppWizard
August 20, 2026
Google has advised Android Auto users experiencing disconnection issues to update to the latest app version. The problem arose with the rollout of Android Auto 17.2, with some users also reporting issues with version 17.1. The disconnection occurs every few minutes, often shortly after launching the app, with users noting that the application freezes after about three minutes. Downgrading to version 17.0 resolves these connectivity issues. Google has implemented a fix and recommends users install at least version 17.4, with version 17.5 now being rolled out. Users may need to manually update if they are on older versions. Additionally, users have expressed dissatisfaction with the new AI-powered assistant, Gemini, which is set to replace Google Assistant, citing issues with basic tasks and app crashes.
AppWizard
August 19, 2026
Google has rolled out Android Auto 17.5, available to both beta and stable users through the Google Play Store. The update lacks a detailed changelog, indicating a focus on behind-the-scenes improvements. Users have reported issues related to the new AI-powered assistant, Gemini, which is set to replace Google Assistant next month, including difficulties with basic tasks and crashes. A bug requires users to unlock their phones to use Android Auto. Users can manually download Android Auto 17.5 using APK installers. Future features include support for widgets and video apps like YouTube, with video functionality available only to YouTube Premium users. The update will continue to roll out over the coming weeks.
Tech Optimizer
August 18, 2026
Executing files directly from the temporary download folder is the primary gateway for infostealers targeting Windows systems, accounting for approximately 35% of analyzed infections. The second most common entry point is C:WindowsMicrosoft.NETFramework, appearing in 32% of cases and associated with advanced tactics like process injection. The findings are based on a report by Kaspersky, which analyzed five million records from the dark web. Malicious files often disguise themselves as legitimate software, such as fake codecs or program activators. Kaspersky recommends monitoring exposed assets and not disabling antivirus software during installations.
Search