Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download Sites — Threadlinqs Intelligence
As of 2026-09-01, Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download Sites is a high-severity malware threat attributed to Void Arachne, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-2283 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Void Arachne · ESPIONAGE
Microsoft Defender Experts is tracking an active campaign distributing malicious installers through fraudulent software-download sites impersonating vendors such as Razer, Microsoft Edge, Kaspersky,
Microsoft Defender Experts telemetry surfaced a campaign in which victims searching for common utility software (Razer Synapse, Microsoft Edge, Kaspersky, Sejda PDF, NetEase Youdao, DiskGenius, Baidu Netdisk, oCam, draw.io, SteelSeries, Sogou, Calibre, and a MindMaster typosquat) land on look-alike .com.cn/.hl.cn domains and download a dynamically generated ZIP archive. The archive filename stays constant across downloads (app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.*) while its SHA-256 hash changes on every request, indicating server-side payload regeneration rather than static hosting; Microsoft observed two content-distinct archives with the same filename fetched 69 seconds apart from a single delivery host.
Execution proceeds through one of two vectors: a wrapper installer (spawned beneath msedge.exe -> an archive tool such as 7zFM.exe/360zip.exe/WinRAR.exe) that drops a randomly named stage-one payload into C:\Users\Public\<random>\<random>.exe or C:\Program Files (x86)\<random>\<random>.exe; or a Windows Installer proxy vector where msiexec.exe -Embedding E Global\MSI0000 launches the payload from C:\Users\Public\, abusing a signed, trusted binary. The implant then establishes SYSTEM-level persistence by creating a short-lived scheduled task (SCHTASKS /Create /RL HIGHEST /RU "SYSTEM") used only to perform privileged Defender-exclusion and registry writes before deleting itself, and separate disguised recurring scheduled tasks (benign corporate-sounding names, ~60-second re-execution cadence, parent svchost.exe -k netsvcs) that relaunch a copy staged at C:\ProgramData\<random>\<random>.exe.
Defense evasion is extensive: broad Add-MpPreference exclusions written to HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths covering C:\ProgramData, C:\Users, C:\Program Files (x86), and C:\; vssadmin delete shadows /all /quiet to inhibit recovery; and a coordinated Windows Update neutralization (stopping/disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, renaming wuaueng.dll/WaaSMedicSvc.dll to *_BAK.dll, deleting the SoftwareDistribution cache, disabling \Microsoft\Windows\WindowsUpdate\* tasks, and setting NoAutoUpdate=1 via HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU). The implant masquerades payload version metadata as a Philips Speech Driver Client Configuration binary (CompanyName "Speech Processing Solutions GmbH"), side-loads malicious DLLs (UxEnhance64.dll at stage one, XPSPLOG.dll at a later stage), hardens its drop directories with icacls, writes a malicious policy to the Windows Defender Application Control code-integrity store, and in one observed instance launched svchost.exe from a non-standard path (D:\hellothere\) rather than C:\Windows\System32\. Process injection via CreateRemoteThread into legitimate user applications is used as an escalation/evasion fallback.
For command and control the implant repurposes the legitimate Indigo Rose TrueUpdate Client (tu_rt.exe v3.8.0.0) to retrieve later-stage payloads over TLS 443 from an Alibaba Cloud OSS bucket (upitem.oss-cn-hangzhou.aliyuncs.com; a second bucket, newopt001.oss-cn-hongkong.aliyuncs.com, was observed hosting innstll.1.0.61.zip). A dedicated C2 tier of six-character .net domains and a small set of dedicated IPs communicates over non-standard ports (5090, 7031, 7032, 7088-7090, 8050, 28290, 28300); Microsoft observed interactive hands-on-keyboard activity alongside automated beaconing, and one attempted SMB lateral-movement connection to an additional host that Defender blocked. Infrastructure analysis at the ASN level (AS132839, AS8796) — rather than netblock/geography grouping, which missed the relationship — tied together delivery and C2 hosts spread across otherwise-unrelated hosting and DNS providers.
Microsoft assesses with moderate confidence that this activity is consistent with the publicly reported Silver Fox (Yinhu / 银狐) actor and has not attributed it to a nation-state. Independent reporting describes Silver Fox (
Target sectors: health, manufacturing, gaming, technology, logistics, government administration, education
Target regions: china, Chinese-speaking regions
Timeline
- Silver Fox (Yinhu / Void Arachne / The Great Thief of the Valley) documented as active since at least 2023, per Trustwave SpiderLabs research.
- The Hacker News reports a related Silver Fox campaign using fake vendor websites to deliver Sainbox RAT (a Gh0st RAT variant) and a Hidden open-source rootkit via side-loaded libcef.dll.
- Trustwave SpiderLabs publishes 'Inside Silver Fox's Den,' documenting the actor's malware arsenal (ValleyRAT, Winos 4.0, Sainbox RAT, Nidhogg/Hidden rootkits) and dual espionage/financial motivation.
- ReliaQuest reports Silver Fox distributing ValleyRAT via a fake Microsoft Teams installer (teamscn[.]com) using Cyrillic-character false-flag tradecraft to mislead attribution toward a Russian actor.
- Cyber Security News reports a Silver Fox campaign using fake tax-audit alerts and software-update lures to deliver ValleyRAT, AtlasCross RAT, and a Catena loader via BYOVD kernel-level EDR/AV disabling.
- Microsoft Defender Experts telemetry begins capturing execution of this counterfeit-installer campaign's stage-one and later-stage payloads (observed intra-day execution timestamps 02:44:20-08:38:51 in single cycles); exact start date approximate, per Microsoft's July 2026 observation window.
- Microsoft Security Blog publishes 'Counterfeit installers to system compromise: Tracking a deceptive software download campaign,' attributing the activity with moderate confidence to Silver Fox and releasing full IOC set and hunting queries.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.006, T1204.002, T1059.001, T1059.003, T1218.007, T1053.005, T1053.005, T1685, T1036.005