SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
SilverFox (Yinhu) Fake Software Download Sites Deliver (TL-2026-2773), also tracked as Silver Fox fake software campaign, is a high-severity malware campaign, first published 2026-09-29. It is attributed to Void Arachne with medium confidence, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1036.005, T1053.005, T1055), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2773
- Threat ID
- TL-2026-2773
- Also known as
- Silver Fox fake software campaign, Counterfeit installers campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution
- Void Arachne
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, manufacturing, gaming, technology, logistics, government administration, education
- Target regions
- china, malaysia
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in SilverFox (Yinhu) Fake Software Download Sites Deliver
Malware and tooling: Ghost RAT, ValleyRAT
Microsoft Defender Experts assess with moderate confidence that a campaign using cloned vendor download sites (browsers, security tools, utilities) is consistent with Silver Fox (aka Yinhu). Sites serve server-side regenerated ZIP installers that drop randomly named payloads, create SYSTEM scheduled tasks, add Defender exclusions, disable Windows Update and delete shadow copies, mainly hitting Chinese-speaking users across several industries.
How SilverFox (Yinhu) Fake Software Download Sites Deliver works
Microsoft Defender Experts (blog dated 2026-09-01) track an active campaign in which counterfeit software-download websites impersonate trusted vendors including Razer, Microsoft Edge, Kaspersky, Sejda PDF, NetEase Youdao, DiskGenius, Baidu Netdisk, oCam, draw.io, SteelSeries, Sogou, Calibre and MindMaster. Lookalike domains sit under .com.cn and .hl.cn. Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox (Yinhu, 银狐) fake-software campaign and has not attributed it to a nation-state. Victims span healthcare and medical devices, manufacturing, gaming, technology, logistics, government and higher education, primarily China-based operations of multinationals and Chinese-speaking users.
The archive keeps the same file name (rotating patterns such as app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.*) but its hash changes on every download, meaning the payload is generated server-side per request. Two archives with identical names were observed arriving about 69 seconds apart with different contents. Single-hash blocking of the archive is therefore ineffective; Microsoft recommends pivoting on the stable payload hashes, drop-path patterns and post-execution behavior instead. This per-request rebuilding is what hampers researchers and signature-based detection.
Extracting the archive launches a wrapper installer (e.g. a_instapp83353001.exe, ainst8663586104.exe) that places a randomized stage-one payload in a world-writable location such as C:\Users\Public\<random>\<random>.exe or C:\Program Files (x86)\<random>\<random>.exe. An alternate route runs the payload through msiexec.exe -Embedding to hide behind Windows Installer. Payloads masquerade as legitimate software (Philips Speech Driver, Indigo Rose TrueUpdate Client) with placeholder version metadata, sideload malicious DLLs (UxEnhance64.dll in stage one, XPSPLOG.dll in later stages), and inject into legitimate user applications through remote-thread creation. Persistence is via scheduled tasks with benign-sounding names (e.g. 'Deadline Mission Target', 'Hierarchy Tools Smooth Inventory') that relaunch payloads from C:\ProgramData\ roughly every 60 seconds; icacls is used to grant Administrators/SYSTEM full control over payload files.
Before hands-on activity the payloads weaken the host: SYSTEM scheduled tasks write Microsoft Defender exclusions (Add-MpPreference -ExclusionPath for C:\ProgramData, C:\Users, C:\Program Files (x86) and C:\), 'vssadmin delete shadows /all /quiet' removes recovery copies, and wuauserv, UsoSvc, uhssvc and WaaSMedicSvc are stopped and disabled, wuaueng.dll is renamed, and the NoAutoUpdate policy is set. C2 traffic uses non-standard ports (5090, 7031, 7032, 7088-7090, 8050, 28290, 28300) to a set of IPs and six-character .net domains, and follow-on payloads are pulled from Alibaba Cloud OSS buckets. Third-party reporting of this campaign (CraftedSignal, summarizing Microsoft) names ValleyRAT (WinOS 4.0) and Gh0st RAT as payloads; the Microsoft text reviewed here did not itself name a final RAT.
A separate, distinct chain documented by Pelagos Intel (report 2026-09-27) reached a Malaysian recipient via WhatsApp: a finance-themed message carried PDF_C2841_20260911100446.zip containing an IMG with a signed launcher (PDF_C2089_20260911100446.exe, KuGou signer metadata) and an unsigned DLL (active_desktop_render_x64.dll posing as dwmapi.dll). The DLL runs an XOR routine, resolves APIs by hash, copies an 11,200-byte buffer to executable memory, stages files under %APPDATA%\Microsoft\Update\, persists through HKCU Run value 'MicrosoftUpdate', and repeatedly beacons to 134.122.155.135:443 (96+ attempts about 3 seconds apart). Pelagos ties this only at ecosystem level to Silver Fox tradecraft, not to the fake-site campaign, so the two sets of indicators should be applied separately.
MITRE ATT&CK techniques used in TL-2026-2773
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1218.007 Msiexec; T1574.001 DLL
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File
Command and Control
T1071 Application Layer Protocol; T1571 Non-Standard Port
defense-impairment
T1112 Modify Registry; T1222.001 Windows Permissions; T1685 Disable or Modify Tools
Impact
T1489 Service Stop; T1490 Inhibit System Recovery
Initial Access
T1566.001 Spearphishing Attachment
Resource Development
Affected products and versions in SilverFox (Yinhu) Fake Software Download Sites Deliver
- Microsoft — Windows
Vulnerable versions: Windows endpoints where users run downloaded installers
Remediation for SilverFox (Yinhu) Fake Software Download Sites Deliver
Immediate actions
- Hunt for the stable payload SHA-256 hashes, C:\Users\Public\<random>\<random>.exe drops and SYSTEM scheduled tasks relaunching payloads from C:\ProgramData
- Block listed C2 IPs, ports and domains plus spoofed vendor and delivery domains at DNS and firewall
- Audit Microsoft Defender exclusions for C:\ProgramData, C:\Users, C:\Program Files (x86) and C:\ and remove unauthorized entries
- Isolate hosts showing vssadmin shadow deletion or wuauserv/UsoSvc/WaaSMedicSvc being disabled
Workarounds
- Enable Tamper Protection to block Defender exclusion and registry writes even from SYSTEM
- Download software only from verified official vendor sites
- Alert on unexpected HKCU Run entries such as 'MicrosoftUpdate' and on msiexec.exe -Embedding launching binaries from C:\Users\Public
Longer-term hardening
- Enable Attack Surface Reduction rules (prevalence/age/trusted-list executable block, obfuscated script block, copied/impersonated system tools block)
- Enable SmartScreen, Network Protection and Microsoft Defender XDR
- Correlate FileOriginUrl landing-page to delivery-host pairs to survive domain rotation
- Block ZIPs named app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.* from lookalike .com.cn/.hl.cn domains
Timeline of SilverFox (Yinhu) Fake Software Download Sites Deliver
- Latest activity timestamps in Microsoft telemetry for the campaign: Task Scheduler execution, injection attempts and Alibaba Cloud storage connections
- Microsoft Defender Experts publish analysis of the counterfeit-installer campaign, assessing consistency with Silver Fox (Yinhu) with moderate confidence
- The Hacker News reports on the campaign, naming ValleyRAT and Gh0st RAT payloads and Windows Update/Defender tampering
- Timestamp 20260911100446 embedded in the WhatsApp lure filenames PDF_C2841_*.zip and PDF_C2089_*.exe analyzed by Pelagos Intel
- Pelagos Intel publishes 'SilverFox in the Desktop' on a WhatsApp-delivered signed-launcher plus sideloaded-DLL chain beaconing to 134.122.155.135:443
- Cyber Security News covers the fake-site campaign and the per-request archive rebuilding that defeats hash-based detection
Sources cited for SilverFox (Yinhu) Fake Software Download Sites Deliver
- Microsoft Security Blog: Counterfeit installers, system compromise: tracking a deceptive software download campaign
- Pelagos Intel: SilverFox in the Desktop
- The Hacker News: Fake Software Installers Disable Windows Update and Defender
- SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
- CraftedSignal: Silver Fox fake installers brief
- TechRadar: Malware installer posing as a legitimate download service infecting brands across almost every industry
More in malware
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)
Detection coverage for TL-2026-2773
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2773 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2773
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.