Skip to content
← All articles
Top Attack·September 2, 2026·Cybersecurity PSA

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Voice options

Voice names come from your browser and device.

Microsoft Security Blog ↗
TL;DR
The fast version

In this article Attack chain overview Campaign scope and targeting Mitigation and protection guidance References Learn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has…

Detailed briefing
Counterfeit installers to system compromise: Tracking a deceptive software download campaign

What happened

The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users.

Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

What is verified

Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (also known as Yinhu, 银狐) fake software campaign but has not attributed it to a nation-state actor.

Organizations should prioritize preventing downloads from untrusted software sources and ensure protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR are enabled to help identify, block, and respond to related activity.

Campaign scope and targeting Microsoft observed affected devices predominantly associated…

Why it matters

The practical risk is that convincing impersonation and social-engineering tactics can turn a single message, login prompt, or support interaction into account takeover or financial fraud. Consumers should treat urgency, requests for credentials, and unexpected payment instructions as signals to verify independently.

What you should do

Verify unusual requests through a trusted channel you initiate yourself. Do not use phone numbers or links supplied in a suspicious message. Use multifactor authentication where available, avoid password reuse, and review account activity after any interaction that may have exposed credentials or payment information.