Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fake Software Installers Threaten Windows Security

Fake Software Installers Threaten Windows Security

Posted on September 2, 2026 By CWS

An ongoing malware campaign is targeting users through fraudulent software download sites, posing as reputable vendors and distributing harmful installers. This campaign has primarily affected China-based operations of multinational organizations and Chinese-speaking users, Microsoft reports.

Malware Targeting Multiple Sectors

The malware campaign has compromised numerous sectors, including healthcare, manufacturing, gaming, and education. The malicious installers, once executed, establish persistence, undermine security defenses, and connect to attacker-operated infrastructure. Microsoft links this activity to a Chinese threat cluster known as Silver Fox, which has a history of using fake vendor websites to spread malware like Gh0st RAT and ValleyRAT.

Fake Websites and Malicious Downloads

The counterfeit websites involved in this campaign are hosted on .com.cn and .hl.cn domains, with Chinese-language content designed to entice downloads of a ZIP archive from “gehie246[.]com.” These sites replicate legitimate vendor pages with a noticeable download prompt, and each download generates a new payload to evade detection.

The downloaded archive contains an installer that initiates the malware payload. Microsoft has identified a secondary method using the Windows Installer service to execute a random executable, further complicating detection. Persistence is achieved through tasks mimicking legitimate IT operations, while the malware alters Microsoft Defender settings, disables Windows Update services, and manipulates file permissions to avoid removal.

Command-and-Control and Ongoing Threats

Following these actions, the malware establishes command-and-control over non-standard ports, utilizing domains “iualef[.]net” and “oijfwe[.]net.” Although the campaign’s ultimate goal remains unclear, Microsoft has employed automated containment measures to mitigate its impact.

Recently, Kaspersky highlighted a similar threat involving a modified Chinese wallpaper tool to deploy ValleyRAT. The malware, operating under a legitimate application’s guise, captures sensitive data and executes advanced functions like system information collection and keystroke logging.

Concluding Thoughts on Cyber Threats

ValleyRAT’s deployment by Silver Fox, which targets organizations globally for espionage and financial gain, underscores the persistent threat of cyber attacks. According to a report by Expel, ValleyRAT has been linked to another group, CuboidalCanine, associated with the GoldenEyeDog network, which has shifted away from Gh0st RAT.

As cyber threats evolve, organizations must remain vigilant against these sophisticated attacks, leveraging robust security measures and staying informed about emerging threats.

The Hacker News Tags:China, cyber attack, cyber espionage, Cybersecurity, DLL Sideloading, fake installers, Gh0st RAT, Malware, Microsoft, Silver Fox, Software Security, Spyware, threat cluster, ValleyRAT, Windows security

Post navigation

Previous Post: AI-Driven Malware Targets Brazilian Financial Systems
Next Post: Google Debuts Gemini 3.8 Flash Cyber for Security Patching

Related Posts

Enhancing SOCs with Multi-Layered Detection Strategies Enhancing SOCs with Multi-Layered Detection Strategies The Hacker News
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse The Hacker News
Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users Notepad++ Official Update Mechanism Hijacked to Deliver Malware to Select Users The Hacker News
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code The Hacker News
Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice The Hacker News
FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Debuts Gemini 3.8 Flash Cyber for Security Patching
  • Fake Software Installers Threaten Windows Security
  • AI-Driven Malware Targets Brazilian Financial Systems
  • UK Strengthens Cybersecurity for Critical Infrastructure
  • StreamRat Android Trojan Exploits Meta Ads for Device Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Debuts Gemini 3.8 Flash Cyber for Security Patching
  • Fake Software Installers Threaten Windows Security
  • AI-Driven Malware Targets Brazilian Financial Systems
  • UK Strengthens Cybersecurity for Critical Infrastructure
  • StreamRat Android Trojan Exploits Meta Ads for Device Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark