An ongoing malware campaign is targeting Windows devices through counterfeit download pages for well-known software brands like Microsoft Edge, Kaspersky, and Razer. The campaign affects various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. It utilizes high-fidelity fraudulent websites that closely mimic legitimate vendors, with observed lure domains such as app-microsoft-edge[.]com[.]cn and kaspersky-lab[.]hl[.]cn. Attackers employ evasion tactics like server-side payload regeneration and create multiple copies of the same archive in quick succession.
Victims are lured into downloading ZIP files that contain a bundled wrapper installer, which activates a stage-one executable in randomized directories. The malware often masquerades as legitimate software, with some payloads impersonating known applications. Persistence is achieved through scheduled tasks with unusual names, and the malware employs various evasion techniques, including deleting shadow copies and altering file permissions.
Microsoft Defender has identified activity across multiple stages of the attack, including delivery, execution, and command-and-control communications. To mitigate risks, organizations are advised to block downloads from unofficial sources, enforce Tamper Protection, and implement Attack Surface Reduction rules. Indicators of compromise (IOCs) include specific lure domains and URLs associated with the campaign.