Counterfeit installers to system compromise: Tracking a deceptive software download campaign
September 1, 2026 · Microsoft Security · Severity: HIGH
In this article Attack chain overview Campaign scope and targeting Mitigation and protection guidance References Learn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users.
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure. Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor. Microsoft Defender detected and disrupted activity across multiple stages of the attack, including automated containment through attack disruption. Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.
Attack chain overview
The campaign follows a consistent attack chain from a spoofed vendor download page to a self-protecting, persistent implant. The stages below trace that chain — initial access, delivery, execution, persistence, privilege escalation, defense evasion, and command and control.

Campaign scope and targeting
Microsoft observed affected devices predominantly associated with China-based operations and Chinese-speaking users, consistent with the Chinese-language lure content and the .com.cn and .hl.cn infrastructure. Confirmed activity spans medical devices and healthcare, manufacturing, gaming, technology, logistics, government, and higher education across multiple organizations and industries.
Initial access: spoofed software-download sites
The entry point is a fraudulent software-download website that spoofs a legitimate vendor. In one case, endpoint telemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from the delivery host gehie246[.]com/712down; two content-distinct copies of the same-named archive were written within roughly 69 seconds — a direct observation of server-side payload regeneration.
Across the estate, FileOriginReferrerUrl telemetry ties each downloaded archive to the impersonation page that served it and to rotating delivery hosts (yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst, n7b8t85zsg[.]com/ins711) and a suspected attacker-controlled Alibaba Cloud Object Storage Service (OSS) bucket. The lure domains predominantly use .com.cn, .hl.cn, and .cn and embed the impersonated brand name.
Delivery: a dynamically generated installer archive
The following examples illustrate how look-alike domains routed users to the same delivery infrastructure while preserving brand-specific lure pages.
When the user selects the download control, Microsoft Edge retrieves a malicious installer archive from a small set of dedicated delivery domains.
pc-razerzone[.]com[.]cn (spoofed Razer download site) → www[.]gehie246[.]com/712down → app_setup.6653004.zip → stage-one loader
A defining characteristic is that the archive keeps the same filename while its hash changes on every download — a strong indicator the payload is generated server-side, per request. Microsoft observed families of same-named archives (app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.*) whose contents differ across downloads while the delivery URL stays constant; the full validated hash set is in the indicators of compromise below.
kaspersky-lab[.]hl[.]cn → hxxp://www.gehie246[.]com/712down
pc-razerzone[.]com[.]cn → hxxp://www.gehie246[.]com/712down
calibre-ebook[.]com[.]cn → hxxp://www.gehie246[.]com/712down
Brand-impersonation infrastructure
The campaign runs a large, uniform set of vendor look-alike pages on .com.cn and .hl.cn domains, each cloning the real product’s branding and presenting a prominent “Download now” button. All funnel to the same delivery and payload infrastructure.
| Impersonated brand | Spoofed domain (defanged) | Category |
| Razer (Synapse driver) | pc-razerzone[.]com[.]cn | Peripherals / drivers |
| Microsoft Edge | app-microsoft-edge[.]com[.]cn | Browser |
| Kaspersky | kaspersky-lab[.]hl[.]cn | Security software |
| Sejda PDF | sejda[.]hl[.]cn | Productivity |
| NetEase Youdao Dictionary | translate-youdao[.]hl[.]cn | Translation |
| DiskGenius | zh-diskgenius[.]com[.]cn | Disk utility |
| Baidu Netdisk (Pan) | baidu-pan[.]com[.]cn | Cloud storage |
| oCam Screen Recorder | ocam-pc[.]com[.]cn | Screen capture |
| draw.io | cn-drawio[.]com[.]cn | Diagramming |
| SteelSeries | steelseries-cn[.]com[.]cn | Peripherals |
| Sogou | gw-sogou[.]com[.]cn | Input method |
| Calibre | calibre-ebook[.]com[.]cn | E-book |
| MindMaster (typosquat) | mindmoster[.]com[.]cn | Mind-mapping |
| Others | pc-codex, jinshan-cibapc, zh-tbtool, web-tbtool, zh-doubaosrf, ieway-cn (all [.]com[.]cn / [.]hl[.]cn) | Various utilities |
Key Takeaways
- Microsoft tracks a deceptive software download campaign where counterfeit installers lead to system compromise through trojanized applications.
- Users should download software only from official vendor websites and verify file hashes before executing installer packages.
- Organizations should review the full article for complete details and implement relevant security measures.