Find notable cyber news and cases, enriched with sources, timelines, and signals.

Silver Fox bogus software-download websites campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based multinational operations and Chinese-speaking users to compromise. The lure pages mimic legitimate software sites and drive downloads from infrastructure such as gehie246[.]com, while the payload chain uses wrapper installers or msiexec.exe to start execution. The activity has affected organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education and includes defenses evasion such as disabling Microsoft Defender and tampering with Windows Update.

Related Happenings

ValleyRAT malicious installer activity

Malware Activity
H score22 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

How related: The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.

About this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...

Vidar infostealer delivered through TikTok and Instagram Reels

Malware Activity
H score27 First: 10.06.2026 19:00 Last: 10.06.2026 19:00 Sources 1

About this happening: Threat actors are using TikTok and Instagram Reels to deliver Vidar infostealer through fake free-software tutorials, putting viewers at risk of credential, fina...

Atlas RAT and related loaders deployed for remote access and credential theft

Malware Activity
H score33 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT

Campaign
H score36 First: 04.05.2026 14:57 Last: 04.05.2026 14:57 Sources 1

About this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...

Timeline

  1. 02.09.2026 19:41 2 articles · 2h ago

    Microsoft discloses bogus software-download campaign targeting popular software seekers

    Initial Disclosure

    Microsoft says an active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers to users looking for popular software. The activity has resulted in compromises across multiple organizations and industries, with impact concentrated in China-based operations of multinational organizations and Chinese-speaking users, and Microsoft assessed the campaign as consistent with Silver Fox (aka Yinhu). The lure sites use Chinese-language content, host ZIP downloads from "gehie246[.]com," and include counterfeit vendor pages such as app-microsoft-edge[.]com[.]cn and kaspersky-lab[.]hl[.]cn. The installers can establish persistence, weaken security protections, create scheduled tasks that configure Microsoft Defender exclusions via PowerShell, delete volume shadow copies, tamper with Windows Update services such as wuauserv and WaaSMedicSvc, and establish C2 over non-standard ports including 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300.

    Show sources