AI News Feed
Market watch
Cybersecurity

Microsoft warns of hackers spoofing download pages of major tech brands to deliver backdoors

Microsoft reveals Silver Fox hackers spoofing download pages of major tech brands to spread backdoor malware.

The campaign is attributed to Chinese hackers that Microsoft presumes to be the group tracked as Silver Fox, also known as Yinhu. The attackers create fraudulent download pages for products from Microsoft, Razer, Kaspersky, NetEase, Baidu NetDisk, oCam ScreenRecorder, SteelSeries, Calibre, MindMaster, and others. Victim organizations seeking these downloads can receive a weaponized installer that functions as a backdoor, offering attackers persistent access for sending and receiving messages.

Once running, the backdoor establishes persistence through scheduled tasks, injects itself into legitimate processes, and weakens Microsoft Defender and Windows Update by creating an exclusion folder and disabling several update-related services. It also deletes backups and enables the deployment of additional payloads.

Microsoft said the victims are primarily Chinese organizations, though the attackers appear to be casting a wide net. The majority of victims were found in medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education.

Microsoft noted that its Defender product detected and disrupted the activity across multiple stages, including automated containment through attack disruption. To defend against Silver Fox's tactics, Microsoft urges organizations to enable tamper protection, which blocks exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM. It also recommends hunting based on behavior rather than file names, setting alerts for tamper sequences, and treating look-alike download archives as malicious in web and mail flows. Microsoft provided a list of indicators of compromise in its report.