A malware campaign impersonating trusted software vendors via counterfeit download sites targets primarily Chinese-speaking users and organizations, deploying malicious installers that disable Windows Update, weaken Microsoft Defender, and establish persistent access. The attacks, linked to the Chinese threat cluster Silver Fox, use scheduled tasks and PowerShell to evade detection, modify system defenses, and communicate with attacker-controlled command-and-control servers. Victims span multiple sectors including healthcare, manufacturing, and government, while the campaign employs sophisticated tactics like DLL sideloading and code-signing certificate abuse to deliver backdoors such as ValleyRAT.
https://thehackernews.com/2026/09/fake-software-installers-disable.html

