Tech News news.wrst.click
🌐 Español
LIVE EDITORIAL
Back to all news
Artificial Intelligence · September 2, 2026 · 2 min read · The Hacker News · 4 views

Malware Campaign Impersonates Legitimate Software and Disables Windows Security

Malware Campaign Impersonates Legitimate Software and Disables Windows Security
📷 Original photo: The Hacker News View original source ↗
Summary

A sophisticated malware campaign is using fraudulent software download websites to impersonate trusted vendors and distribute malicious installers, affecting organizations across critical sectors including healthcare, manufacturing, technology, logistics, government, and education. Microsoft has identified the campaign, attributed with moderate confidence to the Chinese threat cluster Silver Fox (aka Yinhu), which has primarily impacted multinational organizations' China-based operations and Chinese-speaking users. Attackers utilize websites hosted on .com.cn and .hl.cn infrastructure with Chinese-language content to deceive victims and download ZIP files from compromised domains like "gehie246[.]com".

The malicious installers deploy malware capable of establishing persistence through scheduled tasks mimicking routine IT operations, weakening security protections by misconfiguring Microsoft Defender, and deleting volume shadow copies to hinder system recovery. The malware also modifies discretionary access control lists (DACLs) using icacls to protect payload directories and disables critical Windows Update services including wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming update DLL files and deleting the SoftwareDistribution cache. This combination of techniques allows attackers to maintain continuous control over compromised systems.

Once persistence conditions are established, the malware establishes command-and-control (C2) communication using application-layer protocols on non-standard ports such as 5090, 7031, 7032, 7088-7090, 8050, 28290, and 28300, connecting to domains like "iualef[.]net" and "oijfwe[.]net". Kaspersky also documented the use of a modified version of the QN Wallpaper tool to execute DLL sideloading techniques distributing ValleyRAT, a sophisticated backdoor that captures keystrokes, clipboard contents, takes screenshots, and allows attackers to update C2 addresses, download additional modules, and wipe system logs.

The use of ValleyRAT has also been attributed to the sub-group CuboidalCanine within GoldenEyeDog, which uses watering hole techniques and abuses code-signing certificates to bypass security controls. While Silver Fox's motivations include cyber espionage and financial gain, the technical sophistication of the campaign and its ability to disable multiple layers of security protections demonstrate an advanced threat level that requires continuous vigilance and proactive security updates.

← Back to all news ID: falsos-instalado
Summary copied to clipboard