Microsoft Defender Experts is tracking an active campaign in which attackers use counterfeit software download pages to deliver malware through installers that appear legitimate. For small and midsized businesses, this matters because the entry point looks ordinary: a browser, a ZIP archive, and an installer. Microsoft, however, describes a chain with persistence, Microsoft Defender tampering, disabled Windows Update components, and command-and-control connections. This guide explains which signals administrators should review now in Microsoft Defender XDR.
What Microsoft reported on 1 September 2026
The analysis was published on the Microsoft Security Blog. Microsoft observed fake download pages that impersonate trusted vendors and lead users to malicious installer archives. The named examples include spoofed pages for Razer, Microsoft Edge, Kaspersky, Sejda PDF, DiskGenius, Baidu Netdisk, draw.io, and other utilities. The lure domains mainly use .com.cn, .hl.cn, and .cn. Microsoft states that affected devices were predominantly associated with China-based operations of multinational organizations and Chinese-speaking users; confirmed activity spanned several industries, including healthcare, manufacturing, technology, logistics, government, and education.
After execution, the malware establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure, according to Microsoft. Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox campaign, but it does not attribute the activity to a nation-state actor.
Why this affects smaller organizations
Although Microsoft observed most victims in a specific regional context, the pattern is practical for organizations with 10 to 250 seats. Downloads of drivers, PDF tools, browser components, or utilities are routine. That ordinary starting point makes detection harder: the attack begins with a convincing website and a harmless-looking archive, not an obvious exploit alert.
- The initial access path uses spoofed vendor pages rather than traditional email attachments.
- The archives can keep similar names while hashes and payloads change.
- Payloads run from unusual paths such as
C:\Users\Public,C:\ProgramData, orC:\Program Files (x86). - Scheduled tasks relaunch payloads and make file-only cleanup unreliable.
Urgency: active campaign, no migration deadline
Microsoft does not publish a future migration date for this issue; it describes active malicious activity. This is therefore not a migration project, but a control review for existing protections. One detail in Microsoft’s analysis is especially important: Attack Disruption could contain affected devices and accounts, but full eradication of persistence still required responder action. Automatic containment is not the same as remediation.
For Microsoft Defender environments, installer-download alerts, tamper attempts, scheduled tasks, and network connections should be reviewed together. A single detection should not be treated only as blocked malware if there are also signs of changed Defender exclusions or disabled Windows Update services.
Technical signals from Microsoft’s analysis
Microsoft describes several recurring patterns: dynamically generated installer archives, execution through wrappers or msiexec.exe, random executable names in writable system paths, disguised scheduled tasks, and a roughly one-minute re-execution cadence on affected devices. The malware also attempts to weaken Microsoft Defender through broad exclusions, delete shadow copies with vssadmin delete shadows /all /quiet, and disable Windows Update services such as wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc.
Microsoft lists relevant Defender XDR detections, including Defender exclusion changes, suspicious Task Scheduler activity, process injection, potential C2 behavior, blocked lateral SMB movement, and compromised devices or accounts. For Microsoft Defender for Endpoint, Microsoft also publishes Advanced Hunting queries that pivot on path patterns, process chains, Defender tampering, update neutralization, scheduled tasks, and known C2 destinations.
Concrete next steps for administrators
- Review Tamper Protection, SmartScreen, network protection, web content filtering, and cloud-delivered protection on relevant devices.
- Run the Microsoft hunting queries for randomized payload paths, Defender exclusions,
msiexecexecution, and Task Scheduler persistence. - Assess downloads from look-alike domains and suspicious ZIP patterns such as
app_setup.*,zinst.*, orinnstll.*in web and mail flow. - If there are hits, review scheduled tasks, Defender exclusions, update services, shadow copies, and possible lateral movement instead of deleting files only.
- For Security Copilot or Threat Analytics, use Microsoft-backed information as the starting point and document results in a traceable incident process.
For a Microsoft Security Assessment, this becomes a clear test case: does the environment surface counterfeit installers only at download time, or also during persistence, tampering, and follow-on movement?
Official Microsoft sources
- Microsoft Security Blog: Counterfeit installers to system compromise
- Microsoft Learn: Threat analytics in Microsoft Defender XDR
If you want to know whether your Microsoft 365 environment can surface these signals reliably and whether the recommended protections are actually enabled, we can review your security configuration in a focused assessment – get in touch.
What does this mean for your environment?
Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
