Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Malware campaign uses fake websites to distribute malicious software, compromising multiple organizations and industries in China.
Intelligence analysis by Qwen 2.5 (3B)

Microsoft warns of a malware campaign targeting popular software downloads, resulting in compromised organizations and industries in China.
Bad guys made fake websites that look like real ones. They trick people into downloading fake software. Once they have the software, it secretly installs bad stuff on your computer that can spy on you and take control of your computer.
Analysis
{"heading_1":"The Campaign Overview","subheading_1":"Description of the Malware","content_1":"The campaign involves fake software-download websites impersonating trusted vendors to distribute malicious installers. Once launched, these installers deploy malware capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.","subheading_2":"Victims and Impact","content_2":"The campaign has affected healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Microsoft assessed the campaign as consistent with the Chinese threat cluster Silver Fox (Yinhu).","subheading_3":"Technical Details","content_3":"The fake websites use Chinese-language lure content to trigger the download of a ZIP archive from 'gehie246[.]com.' The archive contains a wrapper installer that launches the first stage payload. The malware establishes persistence through scheduled tasks and disables Windows Update services. It also tampers with Windows Update and deletes the SoftwareDistribution cache.","subheading_4":"Detection and Response","content_4":"Microsoft detected the malware and initiated automated containment procedures to limit the attack's impact. The campaign's C2 domains are 'iualef[.]net' and 'oijfwe[.]net.'","subheading_5":"Related Threats","content_5":"The campaign is related to the use of ValleyRAT, a sophisticated implant with features for system information collection, screenshot taking, and malware delivery. The malware is also linked to the use of QN Wallpaper, a modified adware application used for DLL sideloading."}
Key points
- Fake websites impersonate trusted vendors to distribute malicious software
- The malware can set up persistence and communicate with attacker-controlled infrastructure
- The campaign has affected multiple industries and organizations in China
- Microsoft detected the malware and initiated containment procedures
- The malware disables Windows Update services and tampers with the SoftwareDistribution cache
By improving security measures and educating users, we can reduce the chances of falling for fake websites and getting their fake software.
If people keep falling for fake websites, the bad guys will continue to find new ways to trick them and spread their bad software.


