Silver Fox bogus software-download websites campaign
Campaign
Summary
Hide ▲
Show ▼
An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based multinational operations and Chinese-speaking users to compromise. The lure pages mimic legitimate software sites and drive downloads from infrastructure such as gehie246[.]com, while the payload chain uses wrapper installers or msiexec.exe to start execution. The activity has affected organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education and includes defenses evasion such as disabling Microsoft Defender and tampering with Windows Update.
Related Happenings
ValleyRAT malicious installer activity
Malware Activity
H score22
First: 02.09.2026 19:41
Last: 02.09.2026 19:41
Sources 1
How related:
The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.
About this happening:
ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
ValleyRAT malicious installer activity
Malware ActivityHow related: The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.
About this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...
Vidar infostealer delivered through TikTok and Instagram Reels
Malware Activity
H score27
First: 10.06.2026 19:00
Last: 10.06.2026 19:00
Sources 1
About this happening:
Threat actors are using TikTok and Instagram Reels to deliver Vidar infostealer through fake free-software tutorials, putting viewers at risk of credential, fina...
Vidar infostealer delivered through TikTok and Instagram Reels
Malware ActivityAbout this happening: Threat actors are using TikTok and Instagram Reels to deliver Vidar infostealer through fake free-software tutorials, putting viewers at risk of credential, fina...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware Activity
H score33
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
Atlas RAT and related loaders deployed for remote access and credential theft
Malware ActivityAbout this happening: TA4922, a China-linked and likely financially motivated malware activity, has expanded beyond East Asia into Europe and Africa. The group uses Atlas RAT*...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
Campaign
H score36
First: 04.05.2026 14:57
Last: 04.05.2026 14:57
Sources 1
About this happening:
Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
CampaignAbout this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Timeline
-
02.09.2026 19:41 2 articles · 2h ago
Microsoft discloses bogus software-download campaign targeting popular software seekers
Initial DisclosureMicrosoft says an active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers to users looking for popular software. The activity has resulted in compromises across multiple organizations and industries, with impact concentrated in China-based operations of multinational organizations and Chinese-speaking users, and Microsoft assessed the campaign as consistent with Silver Fox (aka Yinhu). The lure sites use Chinese-language content, host ZIP downloads from "gehie246[.]com," and include counterfeit vendor pages such as app-microsoft-edge[.]com[.]cn and kaspersky-lab[.]hl[.]cn. The installers can establish persistence, weaken security protections, create scheduled tasks that configure Microsoft Defender exclusions via PowerShell, delete volume shadow copies, tamper with Windows Update services such as wuauserv and WaaSMedicSvc, and establish C2 over non-standard ports including 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300.
Show sources
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender — thehackernews.com — 02.09.2026 19:41
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender — thehackernews.com — 02.09.2026 19:41