Malware Campaign Disables Windows Update in Corporate China

Malware Campaign Disables Windows Update in Corporate China

First seen 3 Sep 2026, 03:59 UTC Ciberseguridadlatam 75.0

Article Content

Browse articles
ThreatCluster

Microsoft detected an active malware campaign targeting corporate systems in China, where attackers use fake software download sites to distribute malware that disables Windows Update and weakens Microsoft Defender. The malware is disguised as legitimate software, tricking users into installing it while it modifies system settings to prevent updates and reduce antivirus detection capabilities. This tactic allows attackers to maintain access to compromised systems without the risk of being patched. The operation has affected multiple industries and highlights a systematic approach to targeting corporate environments in the region. The campaign is characterized by its use of familiar software interfaces to deceive users, making it a significant threat to organizations relying on Windows systems.

Key Points: • Attackers use fake download sites to distribute malware targeting corporate systems in China. • The malware disables Windows Update and weakens Microsoft Defender to maintain access. • This campaign affects multiple industries, indicating a broad scope of impact.

Timeline

2026-09-03
Microsoft detects malware campaign
Microsoft reported a campaign that uses fake software download sites to distribute malware affecting corporate operations in China.
Ciberseguridadlatam