SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses

SilverFox (Yinhu) Fake Software Download Sites Deliver (TL-2026-2773), also tracked as Silver Fox fake software campaign, is a high-severity malware campaign, first published 2026-09-29. It is attributed to Void Arachne with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1036.005, T1053.005, T1055), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2773

Threat ID
TL-2026-2773
Also known as
Silver Fox fake software campaign, Counterfeit installers campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-29
Last reviewed
2026-09-29
Attribution
Void Arachne
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, manufacturing, gaming, technology, logistics, government administration, education
Target regions
china, malaysia
Detection rules
9
Indicators of compromise
29

Malware and tooling in SilverFox (Yinhu) Fake Software Download Sites Deliver

Malware and tooling: Ghost RAT, ValleyRAT

Microsoft Defender Experts assess with moderate confidence that a campaign using cloned vendor download sites (browsers, security tools, utilities) is consistent with Silver Fox (aka Yinhu). Sites serve server-side regenerated ZIP installers that drop randomly named payloads, create SYSTEM scheduled tasks, add Defender exclusions, disable Windows Update and delete shadow copies, mainly hitting Chinese-speaking users across several industries.

How SilverFox (Yinhu) Fake Software Download Sites Deliver works

Microsoft Defender Experts (blog dated 2026-09-01) track an active campaign in which counterfeit software-download websites impersonate trusted vendors including Razer, Microsoft Edge, Kaspersky, Sejda PDF, NetEase Youdao, DiskGenius, Baidu Netdisk, oCam, draw.io, SteelSeries, Sogou, Calibre and MindMaster. Lookalike domains sit under .com.cn and .hl.cn. Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox (Yinhu, 银狐) fake-software campaign and has not attributed it to a nation-state. Victims span healthcare and medical devices, manufacturing, gaming, technology, logistics, government and higher education, primarily China-based operations of multinationals and Chinese-speaking users.

The archive keeps the same file name (rotating patterns such as app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.*) but its hash changes on every download, meaning the payload is generated server-side per request. Two archives with identical names were observed arriving about 69 seconds apart with different contents. Single-hash blocking of the archive is therefore ineffective; Microsoft recommends pivoting on the stable payload hashes, drop-path patterns and post-execution behavior instead. This per-request rebuilding is what hampers researchers and signature-based detection.

Extracting the archive launches a wrapper installer (e.g. a_instapp83353001.exe, ainst8663586104.exe) that places a randomized stage-one payload in a world-writable location such as C:\Users\Public\<random>\<random>.exe or C:\Program Files (x86)\<random>\<random>.exe. An alternate route runs the payload through msiexec.exe -Embedding to hide behind Windows Installer. Payloads masquerade as legitimate software (Philips Speech Driver, Indigo Rose TrueUpdate Client) with placeholder version metadata, sideload malicious DLLs (UxEnhance64.dll in stage one, XPSPLOG.dll in later stages), and inject into legitimate user applications through remote-thread creation. Persistence is via scheduled tasks with benign-sounding names (e.g. 'Deadline Mission Target', 'Hierarchy Tools Smooth Inventory') that relaunch payloads from C:\ProgramData\ roughly every 60 seconds; icacls is used to grant Administrators/SYSTEM full control over payload files.

Before hands-on activity the payloads weaken the host: SYSTEM scheduled tasks write Microsoft Defender exclusions (Add-MpPreference -ExclusionPath for C:\ProgramData, C:\Users, C:\Program Files (x86) and C:\), 'vssadmin delete shadows /all /quiet' removes recovery copies, and wuauserv, UsoSvc, uhssvc and WaaSMedicSvc are stopped and disabled, wuaueng.dll is renamed, and the NoAutoUpdate policy is set. C2 traffic uses non-standard ports (5090, 7031, 7032, 7088-7090, 8050, 28290, 28300) to a set of IPs and six-character .net domains, and follow-on payloads are pulled from Alibaba Cloud OSS buckets. Third-party reporting of this campaign (CraftedSignal, summarizing Microsoft) names ValleyRAT (WinOS 4.0) and Gh0st RAT as payloads; the Microsoft text reviewed here did not itself name a final RAT.

A separate, distinct chain documented by Pelagos Intel (report 2026-09-27) reached a Malaysian recipient via WhatsApp: a finance-themed message carried PDF_C2841_20260911100446.zip containing an IMG with a signed launcher (PDF_C2089_20260911100446.exe, KuGou signer metadata) and an unsigned DLL (active_desktop_render_x64.dll posing as dwmapi.dll). The DLL runs an XOR routine, resolves APIs by hash, copies an 11,200-byte buffer to executable memory, stages files under %APPDATA%\Microsoft\Update\, persists through HKCU Run value 'MicrosoftUpdate', and repeatedly beacons to 134.122.155.135:443 (96+ attempts about 3 seconds apart). Pelagos ties this only at ecosystem level to Silver Fox tradecraft, not to the fake-site campaign, so the two sets of indicators should be applied separately.

MITRE ATT&CK techniques used in TL-2026-2773

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1218.007 Msiexec; T1574.001 DLL

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File

Command and Control

T1071 Application Layer Protocol; T1571 Non-Standard Port

defense-impairment

T1112 Modify Registry; T1222.001 Windows Permissions; T1685 Disable or Modify Tools

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Initial Access

T1566.001 Spearphishing Attachment

Resource Development

T1583.001 Domains; T1583.006 Web Services

Affected products and versions in SilverFox (Yinhu) Fake Software Download Sites Deliver

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints where users run downloaded installers

Remediation for SilverFox (Yinhu) Fake Software Download Sites Deliver

Immediate actions

  • Hunt for the stable payload SHA-256 hashes, C:\Users\Public\<random>\<random>.exe drops and SYSTEM scheduled tasks relaunching payloads from C:\ProgramData
  • Block listed C2 IPs, ports and domains plus spoofed vendor and delivery domains at DNS and firewall
  • Audit Microsoft Defender exclusions for C:\ProgramData, C:\Users, C:\Program Files (x86) and C:\ and remove unauthorized entries
  • Isolate hosts showing vssadmin shadow deletion or wuauserv/UsoSvc/WaaSMedicSvc being disabled

Workarounds

  • Enable Tamper Protection to block Defender exclusion and registry writes even from SYSTEM
  • Download software only from verified official vendor sites
  • Alert on unexpected HKCU Run entries such as 'MicrosoftUpdate' and on msiexec.exe -Embedding launching binaries from C:\Users\Public

Longer-term hardening

  • Enable Attack Surface Reduction rules (prevalence/age/trusted-list executable block, obfuscated script block, copied/impersonated system tools block)
  • Enable SmartScreen, Network Protection and Microsoft Defender XDR
  • Correlate FileOriginUrl landing-page to delivery-host pairs to survive domain rotation
  • Block ZIPs named app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.* from lookalike .com.cn/.hl.cn domains

Timeline of SilverFox (Yinhu) Fake Software Download Sites Deliver

  • Latest activity timestamps in Microsoft telemetry for the campaign: Task Scheduler execution, injection attempts and Alibaba Cloud storage connections
  • Microsoft Defender Experts publish analysis of the counterfeit-installer campaign, assessing consistency with Silver Fox (Yinhu) with moderate confidence
  • The Hacker News reports on the campaign, naming ValleyRAT and Gh0st RAT payloads and Windows Update/Defender tampering
  • Timestamp 20260911100446 embedded in the WhatsApp lure filenames PDF_C2841_*.zip and PDF_C2089_*.exe analyzed by Pelagos Intel
  • Pelagos Intel publishes 'SilverFox in the Desktop' on a WhatsApp-delivered signed-launcher plus sideloaded-DLL chain beaconing to 134.122.155.135:443
  • Cyber Security News covers the fake-site campaign and the per-request archive rebuilding that defeats hash-based detection

Sources cited for SilverFox (Yinhu) Fake Software Download Sites Deliver

More in malware

Detection coverage for TL-2026-2773

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2773 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2773

6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats