Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Microsoft Warns of Malware Campaign Spoofing Popular Software Brands

Microsoft is warning about an ongoing campaign in which Chinese hackers, reportedly linked to Silver Fox, are creating fraudulent download pages that imitate popular technology and software companies.

The campaign targets organizations that appear to be downloading software from brands including Razer, Kaspersky, Microsoft, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, and MindMaster. Instead, victims receive weaponized installers that primarily function as backdoors.

Once installed, the backdoor gives attackers continued access and enables them to send and receive messages. It creates scheduled tasks for persistence, injects itself into legitimate processes, weakens Microsoft Defender and Windows Update, deletes backups, and can deliver additional payloads.

Most identified victims are Chinese organizations, although Microsoft said the campaign appears to have a wider reach. Victims were mainly found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education.

Microsoft said its Defender product “detected and disrupted” the activity across multiple attack stages, including automated containment through attack disruption. The company advises organizations to enforce tamper Protection, monitor behavior rather than file names, alert on tamper sequences, and treat look-alike download archives as malicious in web and mail flow.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.