The usual search for the program has become a point of entry for a serious infection. Microsoft has revealed a campaign that copies the sites of well-known developers and distributes malicious installers through them. The main goals were Chinese-language users and units of international companies in China.
Fake pages simulated the sites Razer, Microsoft Edge, Kaspersky, Sejda PDF, DiskGenius, Baidu Netdisk, draw.io, Calibre and other products. After clicking the download button, the browser received a ZIP archive with the installer. All the pages sent visitors to the common delivery infrastructure, although they were not connected.
The contents of the archive changed at each download, although the file name and download address could remain the same. Microsoft believes the server created a new build for each query, making it difficult to find a threat by checksums. By the nature of the operation, activity with moderate confidence was associated with the Silver Fox campaign, also known as Yinhu.
After launch, the installer saved files under random names in Windows public and system directories. The malware was fixed through the planner's disguised tasks, obtained SYSTEM rights, and implemented the code into trusted processes. One of the components used the legitimate TrueUpdate mechanism to obtain the next load from Alibaba cloud storage.
The malware then added directories to Microsoft Defender exceptions, removed shadow copies, and disabled Windows Update services. Individual components connected to the control servers through non-standard ports. In some organizations, Microsoft also recorded the manual actions of operators and attempts to switch to neighbouring computers through the SMB protocol.
Microsoft Defender discovered and automatically stopped some of the infections, but the complete removal of the fixed components required the actions of specialists. To reduce the risk, Microsoft advises downloading programs only from official sites, enable SmartScreen, network protection and protection against the substitution of settings. The company also recommends tracking process behavior, as file names, domains, and checksums are constantly changing.
Fake pages simulated the sites Razer, Microsoft Edge, Kaspersky, Sejda PDF, DiskGenius, Baidu Netdisk, draw.io, Calibre and other products. After clicking the download button, the browser received a ZIP archive with the installer. All the pages sent visitors to the common delivery infrastructure, although they were not connected.
The contents of the archive changed at each download, although the file name and download address could remain the same. Microsoft believes the server created a new build for each query, making it difficult to find a threat by checksums. By the nature of the operation, activity with moderate confidence was associated with the Silver Fox campaign, also known as Yinhu.
After launch, the installer saved files under random names in Windows public and system directories. The malware was fixed through the planner's disguised tasks, obtained SYSTEM rights, and implemented the code into trusted processes. One of the components used the legitimate TrueUpdate mechanism to obtain the next load from Alibaba cloud storage.
The malware then added directories to Microsoft Defender exceptions, removed shadow copies, and disabled Windows Update services. Individual components connected to the control servers through non-standard ports. In some organizations, Microsoft also recorded the manual actions of operators and attempts to switch to neighbouring computers through the SMB protocol.
Microsoft Defender discovered and automatically stopped some of the infections, but the complete removal of the fixed components required the actions of specialists. To reduce the risk, Microsoft advises downloading programs only from official sites, enable SmartScreen, network protection and protection against the substitution of settings. The company also recommends tracking process behavior, as file names, domains, and checksums are constantly changing.