Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Microsoft reported an active malware campaign that uses fake software-download sites to impersonate trusted vendors and deliver malicious installers, with victims across multiple industries and China-based operations. The activity is linked with moderate confidence to Silver Fox (Yinhu), and related reporting also ties ValleyRAT delivery to malicious installers and DLL sideloading techniques. #SilverFox #Yinhu #Gh0stRAT #ValleyRAT #QNWallpaper

Keypoints

  • Fake vendor websites are being used to spread malicious software installers.
  • The campaign mainly targets Chinese-speaking users and China-based operations.
  • Microsoft linked the activity with moderate confidence to Silver Fox, also known as Yinhu.
  • The malware sets persistence, weakens defenses, and uses scheduled tasks and Windows tampering.
  • Related reporting shows ValleyRAT being delivered through malicious installers and DLL sideloading.

Read More: https://thehackernews.com/2026/09/fake-software-installers-disable.html