Microsoft Uncovers Malware Campaign Using Fake Software Downloads


microsoft malware campaign
Image credit: Microsoft

A fake software download campaign is using counterfeit websites that impersonate Microsoft, Kaspersky, SteelSeries, Calibre, and other well-known companies to infect Windows PCs.

Microsoft has uncovered the active campaign, which tricks users into downloading malicious installer archives disguised as legitimate applications, utilities, and drivers.

Fake software download campaign uses changing malware files

One of the campaign’s key techniques involves changing the malicious archive every time someone downloads it.

Each download receives a different file hash, which makes simple hash-based malware detection less effective. Security tools that rely heavily on matching previously identified file hashes may therefore struggle to identify each newly generated installer.

Malware disables Windows protections

Once a victim runs the counterfeit installer, the malware downloads additional malicious payloads and makes several changes to the Windows system.

The malware can create Scheduled Tasks to maintain persistence and add Microsoft Defender exclusions that prevent certain files or folders from being scanned.

It can also delete Windows shadow copies, disable services related to Windows Update, and inject malicious code into running processes.

These changes can make the infection more difficult to detect and remove while also limiting recovery options.

Multiple organizations have already been compromised

Microsoft says the campaign has successfully compromised multiple organizations.

Most of the observed activity involved Chinese-speaking users and China-based operations belonging to multinational companies.

Microsoft says the activity may have links to the Silver Fox threat ecosystem, also known as Yinhu. However, the company says it does not currently have enough evidence to make a definitive attribution.

Microsoft recommends downloading software only from trusted sources

Microsoft advises users to download applications, utilities, and hardware drivers only from trusted and official sources.

Users should also carefully inspect website addresses before downloading software, particularly when a site claims to represent a major vendor.

Microsoft recommends keeping SmartScreen enabled, along with Network Protection and Tamper Protection, to reduce the risk of malicious installers compromising Windows systems.

In other security news, Microsoft will allow admins using Autopatch to pause problematic updates. Meanwhile, Microsoft Defender is falsely blocking legitimate Google Search URLs.

Microsoft also plans to strengthen Windows 11 security by turning on Memory Integrity automatically on eligible PCs.

More about the topics: malware, microsoft, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages