Silver Fox Campaign Cripples Windows Security
A Chinese threat group dubbed Silver Fox is running a malware campaign using counterfeit software download sites to deliver malicious installers.

An active malware campaign is distributing malicious installers through bogus software-download websites that impersonate trusted vendors. Microsoft assesses with moderate confidence that the activity is consistent with a Chinese threat cluster known as Silver Fox, also called Yinhu, primarily affecting Chinese-speaking users and the China-based operations of multinational organizations.
The campaign has compromised victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The counterfeit websites are high-fidelity clones of legitimate vendor pages, hosted on .com.cn and .hl.cn infrastructure, and use Chinese-language content to lure users.
Spoofed Download Sites and Delivery
The malicious websites trigger the download of a ZIP archive from the domain gehie246[.]com. The archive maintains the same file name, but its hash changes with every download, indicating the payload is generated server-side for each request. Some of the observed counterfeit websites are listed below.
Execution occurs via a wrapper installer or, in a second observed vector, by abusing the trusted Windows Installer service (msiexec.exe) to launch a randomized executable.
Disabling Defenses and Gaining Persistence
Once launched, the malware establishes persistence through scheduled tasks that mimic routine IT or productivity jobs. A short-lived scheduled task runs as SYSTEM to perform several damaging actions. It configures Microsoft Defender exclusions via PowerShell. It deletes volume shadow copies. The payload also modifies directory permissions using icacls to prevent standard users from removing its files.
The attack cripples Windows Update. It stops and disables the wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc services. The malware renames update dynamic-link libraries (DLLs) and deletes the SoftwareDistribution cache.
Command-and-Control Communication
After disabling security, the malware establishes command-and-control (C2) communication over application-layer protocols on non-standard ports. The C2 domains iualef[.]net and oijfwe[.]net are associated with the activity. Microsoft stated that Defender detected the threat and initiated automated containment procedures through attack disruption to limit its impact. The campaign's ultimate goal remains unclear.
Connections to ValleyRAT and Broader Activity
The disclosure follows a recent Kaspersky report detailing a malicious installer that deploys a modified Chinese desktop wallpaper tool, QN Wallpaper, to initiate a DLL sideloading chain for delivering ValleyRAT. Kaspersky noted the attackers "exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection." ValleyRAT is a sophisticated implant capable of collecting system data, taking screenshots, wiping logs, and exfiltrating keylogger and clipboard contents.
According to Expel, ValleyRAT use has also been attributed to a sub-group within GoldenEyeDog called CuboidalCanine, which targets the gambling industry via watering holes. Security researcher Aaron Walton noted, "This malware isn't unique to any actor, but has been known to be used by GoldenEyeDog." He added that attribution relies on factors beyond the malware family itself due to its public source code.
In June 2026, Chinese authorities reportedly took action against cybercrime cases distributing a new variant of the Silver Fox trojan.





