Counterfeit Software Campaign Compromises Windows Systems

Counterfeit Software Campaign Compromises Windows Systems

First seen 2 Sep 2026, 10:43 UTC Blogs.Microsoftmicrosoft.github.ioGbhackersotx.alienvault.combazaar.abuse.ch 66.5

Article Content

Browse articles
ThreatCluster

A malware campaign is exploiting counterfeit download pages for software like Microsoft Edge, Kaspersky, and Razer to compromise Windows devices. The campaign primarily targets users in China and Chinese-speaking regions, affecting sectors such as healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft has linked this activity to the Silver Fox campaign but has not attributed it to any nation-state actor. The attack method involves spoofed download sites that deliver malicious installers, which establish persistence and communicate with attacker-controlled infrastructure. Microsoft Defender has detected and disrupted various stages of the attack. Organizations are advised to avoid untrusted software sources and enable security protections like SmartScreen and Microsoft Defender XDR. The campaign has been detected across multiple organizations, indicating a broad impact.

Key Points: • Counterfeit download pages for trusted software brands are being exploited. • The campaign targets primarily Chinese-speaking users across various sectors. • Microsoft Defender has disrupted multiple stages of the attack.

Timeline

2026-09-01
Microsoft reports on malware campaign
Microsoft disclosed an active malware campaign using counterfeit software-download sites to compromise Windows devices.
Blogs.Microsoft
2026-09-02
Gbhackers covers the malware campaign
Gbhackers reported on the same malware campaign, detailing the use of fake installers for Microsoft Edge, Kaspersky, and Razer.
Gbhackers