Malware Campaign Targets Users Through Bogus Software Downloads
An active malware campaign has emerged, leveraging counterfeit software-download websites to mimic trusted vendors and distribute malicious installers. This initiative has primarily targeted users seeking popular software, leading to compromises across various organizations and industries, with a notable impact on China-based operations of multinational corporations and Chinese-speaking users, as reported by Microsoft.
The malicious installers, once executed, deploy malware capable of establishing persistence, undermining security measures, and communicating with infrastructure controlled by attackers. Victims have been identified across multiple sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education.
Microsoft has assessed with moderate confidence that this campaign aligns with a Chinese threat cluster known as Silver Fox (also referred to as Yinhu), which has a history of utilizing spoofed vendor download pages to disseminate Gh0st RAT and ValleyRAT (also known as WinOS 4.0).
The websites associated with this campaign are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content designed to entice users into downloading a ZIP archive from “gehie246[.]com.” A selection of these counterfeit websites includes:
- app-microsoft-edge[.]com[.]cn
- baidu-pan[.]com[.]cn
- calibre-ebook[.]com[.]cn
- cn-drawio[.]com[.]cn
- gw-sogou[.]com[.]cn
- kaspersky-lab[.]hl[.]cn
- mindmoster[.]com[.]cn
- ocam-pc[.]com[.]cn
- pc-razerzone[.]com[.]cn
- sejda[.]hl[.]cn
- steelseries-cn[.]com[.]cn
- translate-youdao[.]hl[.]cn
- zh-diskgenius[.]com[.]cn
These web pages are sophisticated replicas of legitimate vendor sites, prominently featuring calls to action for downloads. Notably, the downloaded archive retains the same file name, but its hash changes with each download, indicating that the payload is dynamically generated on the server for every request.
Upon opening the archive, users encounter a wrapper installer (e.g., “a_instapp83353001.exe” or “ainst8663586104.exe”), which initiates the first stage of the payload. Microsoft has also identified a secondary execution method that utilizes the trusted Windows Installer service (“msiexec.exe”) to launch a randomized executable, maintaining the same deceptive pattern as the wrapper chain.
Regardless of the delivery method, the malware achieves persistence through scheduled tasks that mimic routine IT or productivity operations. It also creates a temporary scheduled task that runs with SYSTEM privileges, configuring Microsoft Defender exclusions via PowerShell, deleting volume shadow copies, and preventing standard users from removing payload directories by altering their discretionary access control lists (DACLs) using icacls.
Moreover, the malware interferes with Windows Update by halting and disabling services such as wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, while renaming update dynamic-link libraries (DLLs) and purging the SoftwareDistribution cache.
Once these actions are completed, the malware establishes command-and-control (C2) communication over application-layer protocols on non-standard ports, including 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains linked to this activity are “iualef[.]net” and “oijfwe[.]net.”
The ultimate objective of this campaign remains unclear; however, Microsoft has indicated that Defender has detected the threat and initiated automated containment procedures to mitigate its impact.
This disclosure follows closely on the heels of Kaspersky’s report detailing a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, which initiates a DLL sideloading chain responsible for delivering ValleyRAT.
Kaspersky noted that the original version of QN Wallpaper is legitimate adware that, upon installation, delivers bundled partner applications and displays advertisements. In this instance, however, attackers exploit it to execute DLL sideloading, allowing malicious code to run under the guise of a signed process.
The backdoor created through this method not only takes measures to protect its process from termination but also captures keystrokes and clipboard contents, saving this information to a file on disk. Additionally, it periodically scans for active windows belonging to applications that could be used for process or traffic analysis.
ValleyRAT is a sophisticated implant equipped with a broad array of features, enabling it to collect system information, reboot or shut down the computer, capture screenshots, erase logs, update C2 addresses, download additional DLL or shellcode modules, and transmit keylogger logs along with clipboard data.
Kaspersky emphasized that the attackers have leveraged a well-known adware application to execute the backdoor under the guise of a signed process, complicating detection efforts. Motivated by both cyber espionage and financial gain, Silver Fox has targeted organizations across various countries.
A recent report by Expel highlighted that the use of ValleyRAT has also been linked to a subgroup within GoldenEyeDog known as CuboidalCanine, which is believed to have shifted away from Gh0st RAT at some point. This subgroup is noted for targeting the gambling industry and employing watering holes to distribute malware, exploiting code-signing certificates to bypass security controls.
According to security researcher Aaron Walton, “This malware isn’t unique to any actor, but has been known to be used by GoldenEyeDog. Due to the public availability of the source code, attributing this malware to any specific actor depends on factors beyond the malware family itself.”
In June 2026, Chinese authorities took measures against a series of cybercrime cases involving a new variant of the Silver Fox trojan, as reported by the state media outlet China Daily.