Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Minneapolis shooting kills two, wounds three police officers | News

    September 3, 2026

    Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing

    September 3, 2026

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Minneapolis shooting kills two, wounds three police officers | News
    • Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing
    • Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
    • Billionaire Ricardo Salinas Tells People To Escape Fiat
    • DOJ Blocked Charges Against ICE Agent Accused of Shooting Julio Cesar Sosa-Celis, Prosecutor Says — ProPublica
    • Did Trump order that weeping willows be cut down outside Kennedy Center?
    • Inside Trump’s Second Term – The New York Times
    • The far-right leader pushing Germans to forget the Nazi past – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

    “The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft said.

    The installers, once launched, deploy malware that’s capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.

    The activity has resulted in victims spanning healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (aka WinOS 4.0).

    Cybersecurity

    The websites observed as part of the campaign are hosted on the .com.cn and .hl.cn infrastructure and use Chinese-language lure content to trigger the download of a ZIP archive from “gehie246[.]com.” Some of the counterfeit websites are listed below –

    • app-microsoft-edge[.]com[.]cn
    • baidu-pan[.]com[.]cn
    • calibre-ebook[.]com[.]cn
    • cn-drawio[.]com[.]cn
    • gw-sogou[.]com[.]cn
    • kaspersky-lab[.]hl[.]cn
    • mindmoster[.]com[.]cn
    • ocam-pc[.]com[.]cn
    • pc-razerzone[.]com[.]cn
    • sejda[.]hl[.]cn
    • steelseries-cn[.]com[.]cn
    • translate-youdao[.]hl[.]cn
    • zh-diskgenius[.]com[.]cn

    The web pages are high-fidelity clones of the legitimate vendor’s site and feature a prominent download call-to-action. Tellingly, the archive downloaded from the site maintains the same file name while its hash changes on every download, indicating that the payload is generated server-side on the fly for every request.

    Opening the archive leads to a wrapper installer (e.g., “a_instapp83353001.exe” or “ainst8663586104.exe”), which, upon execution, launches the first stage payload. Separately, Microsoft said it observed a second execution vector that makes use of the trusted Windows Installer service (“msiexec.exe”) to launch a randomized executable, mirroring the same masquerade pattern as the wrapper chain.

    Regardless of the method used, persistence is achieved through scheduled tasks that imitate routine IT or productivity jobs. The malware is also responsible for creating a short-lived scheduled task that runs as SYSTEM and configures Microsoft Defender exclusions via PowerShell, deletes volume shadow copies, and ensures payload directories cannot be removed by standard users by modifying their discretionary access control lists (DACLs) using icacls.

    In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update dynamic-link libraries (DLLs), and deleting the SoftwareDistribution cache.

    Once all these steps are carried out, the malware establishes command-and-control (C2) over application-layer protocols on non-standard ports like 5090, 7031, 7032, 7088–7090, 8050, 28290, and 28300. Two C2 domains associated with the activity are “iualef[.]net” and “oijfwe[.]net.”

    It’s unclear what the end goal of the campaign is, as Microsoft said Defender detected and initiated automated containment procedures through attack disruption to limit the attack’s impact further.

    The disclosure comes merely days after Kaspersky detailed a malicious installer that deploys a modified Chinese desktop wallpaper management tool known as QN Wallpaper, while using it to initiate a DLL sideloading chain responsible for delivering ValleyRAT.

    “The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user,” Kaspersky said. “In this case, however, the attackers use it to carry out DLL sideloading, a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL.”

    The backdoor, besides taking steps to protect its process and prevent it from being terminated, captures keystrokes and clipboard contents, and saves the contents to a file on disk. It also periodically scans for active windows belonging to applications that could be used to analyze processes or traffic.

    Cybersecurity

    ValleyRAT is a sophisticated implant with a wide range of features that allows it to collect system information, reboot/shut down the computer, take screenshots, wipe logs, update C2 addresses, download additional DLL or shellcode modules, and send keylogger logs along with clipboard data.

    “The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection,” Kaspersky said. “Motivated by both cyber espionage and financial gain, Silver Fox targets organizations across multiple countries.”

    According to a report published by Expel last month, the use of ValleyRAT has also been attributed to a sub-group within GoldenEyeDog known as CuboidalCanine, which is assessed to have moved away from Gh0st RAT “at some point.” CuboidalCanine, per the cybersecurity company, targets the gambling industry and uses watering holes to distribute the malware by abusing code-signing certificates to bypass security controls.

    “This malware isn’t unique to any actor, but has been known to be used by GoldenEyeDog,” security researcher Aaron Walton said. “Due to the source code being public, attribution of this malware to any actor relies on factors other than the malware family itself.”

    In June 2026, Chinese authorities took action against a series of cybercrime cases distributing a new variant of the Silver Fox trojan, state media outlet China Daily reported.

    defender disable Fake installers Microsoft software update weaken Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

    Malicious Virtualizor Update Served via BGP Hijacking

    Exploit Published for Fresh Cleo Harmony Vulnerability

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Minneapolis shooting kills two, wounds three police officers | News

    September 3, 2026

    Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing

    September 3, 2026

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    September 3, 2026

    Billionaire Ricardo Salinas Tells People To Escape Fiat

    September 3, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Minneapolis shooting kills two, wounds three police officers | News

    September 3, 2026

    Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing

    September 3, 2026

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.