Microsoft Defender Experts tracked a deceptive software-download campaign using counterfeit vendor websites and dynamically generated malicious installer archives to compromise victims. The activity primarily targeted China-based operations of multinational organizations and Chinese-speaking users in healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft assessed with moderate confidence that the operation is consistent with the publicly reported Silver Fox (also known as Yinhu) threat activity, while stopping short of nation-state attribution.
The malware established persistence through scheduled tasks, abused msiexec and a repurposed TrueUpdate runtime, weakened Microsoft Defender and Windows Update protections, deleted shadow copies, injected into processes, and communicated with attacker infrastructure through non-standard ports and Alibaba Cloud OSS. Microsoft Defender detected and disrupted elements of the operation, including command-and-control traffic, attempted SMB lateral movement, and hands-on-keyboard activity; however, incident responders still needed to remove the attackers' persistence mechanisms.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In April 2026, CylindricalCanine reportedly compromised a DigiCert support user's device and intercepted code-signing certificates intended for DigiCert customers. The group then used the intercepted certificates to sign Golden Gh0st Loader malware.
Microsoft reported that the Silver Fox-linked counterfeit-installer campaign establishes scheduled-task persistence, creates SYSTEM-level tasks and PowerShell exclusions to weaken Microsoft Defender, and may delete shadow copies and disable Windows Update. Microsoft also observed hands-on-keyboard activity and attempted SMB lateral movement, and published associated delivery, staging, C2, and payload indicators.
Microsoft Defender Experts tracked an active campaign using counterfeit software-download sites and dynamically generated malicious installer archives to compromise victims, primarily China-based multinational operations and Chinese-speaking users. Microsoft assessed with moderate confidence that the activity was consistent with the publicly reported Silver Fox (Yinhu) campaign and reported detecting and disrupting portions of the activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 70 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcethehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourceotx.alienvault.com
Open sourceexpel.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.