Microsoft reported an active malware campaign that uses fake software-download sites to impersonate trusted vendors and deliver malicious installers, with victims across multiple industries and China-based operations. The activity is linked with moderate confidence to Silver Fox (Yinhu), and related reporting also ties ValleyRAT delivery to malicious installers and DLL sideloading techniques. #SilverFox #Yinhu #Gh0stRAT #ValleyRAT #QNWallpaper
Keypoints
- Fake vendor websites are being used to spread malicious software installers.
- The campaign mainly targets Chinese-speaking users and China-based operations.
- Microsoft linked the activity with moderate confidence to Silver Fox, also known as Yinhu.
- The malware sets persistence, weakens defenses, and uses scheduled tasks and Windows tampering.
- Related reporting shows ValleyRAT being delivered through malicious installers and DLL sideloading.
Read More: https://thehackernews.com/2026/09/fake-software-installers-disable.html