Home / Technology / Microsoft Exposes Fake Downloads

Microsoft Exposes Fake Downloads

Summary

  • Chinese hackers spoof download sites of major tech brands.
  • Backdoored software disables security and deletes backups.
  • Victims include healthcare, gaming, and government sectors.
Microsoft Exposes Fake Downloads

Cybercriminals, believed to be the Chinese group Silver Fox, are actively spoofing download sites for numerous major technology and software companies. Microsoft researchers discovered these fraudulent pages, which lead victims to download weaponized versions of legitimate software that function primarily as backdoors. Once installed, these implants provide attackers with a persistent foothold, allowing them to maintain access and deploy further malicious payloads.

The backdoor is designed to establish persistence through scheduled tasks and inject itself into legitimate processes. Critically, it weakens defenses by creating exclusion folders for Microsoft Defender and disabling key Windows Update services. It also deletes backups, leaving victims vulnerable. While Chinese organizations are the primary targets, the campaign's reach is extensive, affecting sectors including medical devices, healthcare, manufacturing, gaming, technology, logistics, government, and higher education.

Microsoft Defender has successfully detected and disrupted this activity at multiple stages. To combat these threats, Microsoft recommends enforcing tamper protection to prevent modifications to Defender settings. Furthermore, defenders are advised to focus on behavioral detection rather than file names, set up alerts for tamper sequences, and treat look-alike download archives as malicious. Indicators of Compromise are available for enhanced threat hunting.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571