DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign

DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign
Microsoft tracked a fake software download campaign that impersonated trusted vendors and pushed malicious installers, with the activity mainly affecting multinational organizations’ China-based operations and Chinese-speaking users. The investigation linked the campaign to patterns consistent with prior Silver Fox fake software activity and uncovered multiple domain, subdomain, IP, and email-connected artifacts, including malicious domains such as oijfwe[.]net and ai-claude[.]com[.]cn. #SilverFox #oijfwe #ai-claude

Keypoints

  • Microsoft identified a malware campaign that used fake software download sites to impersonate trusted vendors and distribute malicious installers.
  • The campaign primarily affected multinational organizations’ China-based operations, with Chinese-speaking users also identified as a target audience.
  • Researchers assessed with moderate confidence that the activity was consistent with previously reported Silver Fox fake software campaigns, but no nation-state attribution was made.
  • Seven domain IoCs were provided in the Microsoft report, but one was excluded after checks showed it belonged to a legitimate entity.
  • Analysis of the remaining network IoCs revealed typosquatting groups, a likely malicious registration, and multiple IP and domain relationships connected to the campaign.
  • The investigation also uncovered 1,474 email-connected domains, including five already associated with malicious activity, plus additional IP-connected and string-connected domains.
  • Sample network traffic showed two potential victim IPs communicating with one malicious IP IoC, and historical DNS data showed extensive domain-to-IP and IP-to-domain resolution activity.

MITRE Techniques

  • [T1566.001 ] Spearphishing Attachment – The campaign delivered malicious installers through fake download sites that impersonated trusted vendors, luring users into running them (‘users looking for popular software but instead ended up with compromised organizations’).
  • [T1583.001 ] Acquire Infrastructure: Domains – The threat actors registered or used multiple domains, including typosquatted and maliciously intended domains (‘two domain IoCs appeared in two separate typosquatting groups’ and ‘one domain IoC—oijfwe[.]net—was likely registered with malicious intent’).
  • [T1583.006 ] Acquire Infrastructure: Web Services – The infrastructure included hosted subdomains and third-party hosting/site builder services (‘it is hosted on an IP address with 89 other subdomains’ and ‘Third-party hosting/site builder’).
  • [T1036 ] Masquerading – The domains imitated trusted software brands and vendors to appear legitimate (‘app-microsoft-edge[.]com[.]cn’, ‘pc-razerzone[.]com[.]cn’, and ‘kaspersky-lab[.]hl[.]cn’).
  • [T1055 ] Process Injection – The article references malicious installers, but no explicit process injection is described; included only if installer behavior is later confirmed (‘malicious installers’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The campaign relied on web-based downloads and HTTP/S-accessible infrastructure (‘fake software download sites’ and domain-to-IP resolution activity).
  • [T1105 ] Ingress Tool Transfer – Malicious installers were distributed via download sites, indicating tool delivery from external infrastructure (‘distribute malicious installers’).

Indicators of Compromise

  • [Domains ] Typosquatting and malicious domain infrastructure – app-microsoft-edge[.]com[.]cn, pc-razerzone[.]com[.]cn, and 1,474 email-connected domains including ai-claude[.]com[.]cn
  • [Subdomains ] Fake installer hosting and related hostnames – the subdomain tied to aliyuncs[.]com and hostnames under thepacificlmc[.]com / thepacificxxs[.]com groups
  • [IP addresses ] Communication and resolution infrastructure – 202[.]95[.]14[.]237 and one other IP IoC, plus 3 additional IP addresses found during expansion
  • [Email-connected domains ] Historical email reuse led to additional linked domains – 1,474 distinct email-connected domains, with five confirmed malicious
  • [Historical DNS resolutions ] Domain-to-IP and IP-to-domain resolution activity – oijfwe[.]net (520 resolutions), iualef[.]net (360 resolutions), and 1,005 historical IP-to-domain resolutions tied to one IP
  • [File/installer references ] Malicious installer activity referenced in the campaign – fake software installers and malicious installers distributed from impersonation sites


Read more: https://circleid.com/posts/dns-spotlight-silver-fox-strikes-anew-with-a-fake-installer-campaign