Silver Fox Hackers Target China-Based Organizations With Counterfeit Software Installers

The operation has affected organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education.

Attackers lure victims with convincing copies of legitimate software vendor websites, offering downloads for popular tools, drivers, browsers, security products, and utilities.

The attackers use look-alike domains that imitate brands including Razer, Microsoft Edge, Kaspersky, Calibre, SteelSeries, Baidu Netdisk, Sogou, and draw.io.

For example, the campaign used pc-razerzone[.]com[.]cn and app-microsoft-edge[.]com[.]cn to host fraudulent download pages.

These pages contain a prominent “Download now” button that redirects users to malicious ZIP archives hosted on separate delivery infrastructure.

Microsoft found that archives such as app_setup., zinst., zintall., intsoft., and innstll.* were dynamically generated for each download.

Silver Fox Targets China

This technique allows the attackers to retain the same archive name while changing the file hash and internal contents. As a result, simple hash-based detection may be less effective.

After a victim extracts and runs the installer, a wrapper executable creates a malware payload in randomized folders under locations such as C:\Users\Public\, C:\ProgramData\, or C:\Program Files (x86)\. The malware also uses randomized filenames to make identification harder.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control (Source: microsoft)
Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control (Source: microsoft)

In some cases, the campaign abuses the trusted Windows Installer process, msiexec.exe, to launch malicious payloads. It also disguises malware as legitimate software, including a fake Philips Speech driver configuration program.

Silver Fox malware establishes persistence through scheduled tasks with misleading names, such as “Deadline Mission Target” and “Hierarchy Tools Smooth Inventory.” These tasks repeatedly launch payloads from hidden or randomized directories, often at intervals of about 60 seconds.

The malware attempts to gain SYSTEM-level privileges by creating a temporary scheduled task, performing privileged actions, and deleting the task immediately afterward. This approach helps reduce evidence left on the compromised device.

Microsoft observed attackers trying to weaken endpoint defenses by adding broad Microsoft Defender exclusions, deleting volume shadow copies, modifying file permissions, and disabling Windows Update-related services.

The malware may also inject code into legitimate processes, allowing it to operate under the context of trusted applications.

Counterfeit Microsoft Edge download page hosted on the look-alike domain app-microsoft-edge[.]com[.]cn, with a prominent download button (Source: microsoft)
Counterfeit Microsoft Edge download page hosted on the look-alike domain app-microsoft-edge[.]com[.]cn, with a prominent download button (Source: microsoft)

For command-and-control, payloads connect to attacker infrastructure through unusual ports, including 5090, 7031, 8050, and 28300.

Some malware components also contact Alibaba Cloud Object Storage Service buckets over encrypted HTTPS connections to retrieve additional payloads.

Microsoft Defender detected and disrupted parts of the operation through SmartScreen, Network Protection, Defender Antivirus, endpoint detection, and attack disruption capabilities.

The company also detected attempted SMB-based lateral movement and hands-on-keyboard activity in some affected environments, Microsoft said.

Indicators of Compromise

Campaign LayerIndicatorTypeDescription
Lure / Impersonationpc-razerzone[.]com[.]cnDomainFake Razer software download website
Lure / Impersonationapp-microsoft-edge[.]com[.]cnDomainCounterfeit Microsoft Edge download pag

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories