discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Malware campaign uses fake websites to distribute malicious software, compromising multiple organizations and industries in China.

By Ravie Lakshmanan·Sep 2·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Image: thehackernews.com

Microsoft warns of a malware campaign targeting popular software downloads, resulting in compromised organizations and industries in China.

Why it matters

This malware campaign poses a significant threat to cybersecurity, compromising multiple organizations and industries in China.

Bad guys made fake websites that look like real ones. They trick people into downloading fake software. Once they have the software, it secretly installs bad stuff on your computer that can spy on you and take control of your computer.

Analysis

{"heading_1":"The Campaign Overview","subheading_1":"Description of the Malware","content_1":"The campaign involves fake software-download websites impersonating trusted vendors to distribute malicious installers. Once launched, these installers deploy malware capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.","subheading_2":"Victims and Impact","content_2":"The campaign has affected healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Microsoft assessed the campaign as consistent with the Chinese threat cluster Silver Fox (Yinhu).","subheading_3":"Technical Details","content_3":"The fake websites use Chinese-language lure content to trigger the download of a ZIP archive from 'gehie246[.]com.' The archive contains a wrapper installer that launches the first stage payload. The malware establishes persistence through scheduled tasks and disables Windows Update services. It also tampers with Windows Update and deletes the SoftwareDistribution cache.","subheading_4":"Detection and Response","content_4":"Microsoft detected the malware and initiated automated containment procedures to limit the attack's impact. The campaign's C2 domains are 'iualef[.]net' and 'oijfwe[.]net.'","subheading_5":"Related Threats","content_5":"The campaign is related to the use of ValleyRAT, a sophisticated implant with features for system information collection, screenshot taking, and malware delivery. The malware is also linked to the use of QN Wallpaper, a modified adware application used for DLL sideloading."}

Key points

  • Fake websites impersonate trusted vendors to distribute malicious software
  • The malware can set up persistence and communicate with attacker-controlled infrastructure
  • The campaign has affected multiple industries and organizations in China
  • Microsoft detected the malware and initiated containment procedures
  • The malware disables Windows Update services and tampers with the SoftwareDistribution cache
The Upside

By improving security measures and educating users, we can reduce the chances of falling for fake websites and getting their fake software.

The Downside

If people keep falling for fake websites, the bad guys will continue to find new ways to trick them and spread their bad software.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarecybersecuritychinawindows-update

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 2, 2026

Source

thehackernews.com

Share

Topics

securitymalwarecybersecuritychinawindows-update

Related

More from this desk

Sep 2·bleepingcomputer.com

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Hackers are exploiting a vulnerability in Sangoma Switchvox VoIP platform, leading to remote code execution and reverse shell deployment.

Sep 2·bleepingcomputer.com

Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens

Hackers exploit JFrog Artifactory flaw to create admin tokens, gaining administrative access. JFrog addresses the issue with new versions.

Sep 2·bleepingcomputer.com

Dropbox accounts breached through Lenovo email verification flaw

Dropbox warns some users that unauthorized party accessed their accounts through Lenovo's email verification flaw. 5,000 accounts were accessed, and hacker viewed and downloaded content from some users.

Communicating Under Pressure: Best Practices for Service Providers

Sep 2·cisa.gov

Communicating Under Pressure: Best Practices for Service Providers

CISA and FBI provide guidance on clear, timely, accurate, and audience-appropriate communications during IT and OT outages, emphasizing clarity, accountability, and transparency.