Security1 distinct publisher2 min readPublished
Microsoft Defender Experts says fake Kaspersky, Razer and Calibre download sites all funnel to one delivery host that rebuilds the installer per request, which leaves hash blocking almost nothing durable to match.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
This chain's durable artifact is the referrer URL. Microsoft's FileOriginReferrerUrl telemetry ties each downloaded archive back to the impersonation page that served it, plus rotating delivery hosts at yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst and n7b8t85zsg[.]com/ins711, and a suspected attacker-controlled Alibaba Cloud Object Storage bucket [9]. A hunt query can hold onto that referrer chain, but not the file itself: Microsoft counted at least five same-named archive families, app_setup.*, zinst.*, zintall.*, intsoft.* and innstll.*, whose contents differ between requests while the delivery URL stays put [7][14].
The scale of that shows in the numbers. On one device, two content-distinct copies of app_setup.6653004.zip were written roughly 69 seconds apart from the same constant URL after a visit to the fake Razer page pc-razerzone[.]com[.]cn [6]. If the server builds a payload per request, then a hash added to a blocklist covers exactly one download, and 69 seconds is the gap between two observations rather than a rotation interval to tune against [15].
Behind the brand pages there is less infrastructure than the variety suggests. Kaspersky, Razer and Calibre look-alikes on .hl.cn and .com.cn all pointed at www.gehie246[.]com/712down, three unrelated vendors sharing one delivery path [8][13]. Microsoft describes a large uniform set of these pages, each cloning real product branding behind a prominent download button, all funnelling to the same payload infrastructure [10]. Taking down one lure page leaves the shared delivery infrastructure behind it untouched.
What lands establishes persistence, attempts to weaken security protections, and calls attacker infrastructure [4], with privilege escalation and defense evasion sitting between execution and command and control in the chain Microsoft published [12]. Defender caught and disrupted it at several of those stages, including automated containment [11]. Note the order of Microsoft's own guidance: prevent downloads from untrusted software sources first, then SmartScreen, network protection, tamper protection and XDR [5]. The first item is a procurement and allowlisting decision about permitted sources, while the rest are product toggles.
This is one publisher's telemetry, and Microsoft puts only moderate confidence on the activity matching the publicly reported Silver Fox, or Yinhu, fake-software campaign, with no nation-state attribution [3]. Victim concentration is regional [2], but nothing in the mechanism is: it works wherever a user fetches an installer themselves. Choosing which sources may supply software is what resolves a payload that is unique per victim, not detection tuning, and that choice sits with whoever owns the software request path rather than the SOC.
Ranked by verification strength, evidence, and original report placement.
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites impersonating trusted vendors to distribute malicious installers, resulting in compromises across multiple organizations and industries.
Affected devices were predominantly associated with China-based operations of multinational organizations and Chinese-speaking users; confirmed activity spans medical devices and healthcare, manufacturing, gaming, technology, logistics, government and higher education.
Microsoft assesses with moderate confidence that the activity is consistent with the publicly reported Silver Fox (also known as Yinhu) fake software campaign, but has not attributed it to a nation-state actor.
Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure.
Microsoft advises organizations to prioritize preventing downloads from untrusted software sources and to ensure SmartScreen, network protection, tamper protection and Microsoft Defender XDR are enabled.
Endpoint telemetry captured a device navigating to the fake Razer page pc-razerzone[.]com[.]cn and downloading app_setup.6653004.zip from delivery host gehie246[.]com/712down; two content-distinct copies of the same-named archive were written within roughly 69 seconds, a direct observation of server-side payload regeneration.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
ClickFix scales by asking employees to paste the command themselves1 distinct publisher
leadership
Attackers reached a domain controller through one exposed SolarWinds helpdesk1 distinct publisher
security
Silver Fox times ValleyRAT to India's GST deadline behind a real Microsoft signature1 distinct publisher
security
Attackers bought five working browser extensions and shipped malware through auto-update1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Concrete detail, one witness
The specificity is the strong part: a named lure page, a named delivery path, five archive naming families, three rotating delivery hosts, and one telemetry pair where the same filename arrived twice with different contents about a minute apart. Claims that precise are falsifiable in principle. In practice all of them come from a single Defender feed described by Microsoft, the validated hash set is referred to rather than shown in what we have, and the infrastructure enrichment is honestly flagged as two procurement channels rather than two independent signals — a caveat that also applies to the reporting as a whole.
Real victims, no arithmetic
Compromise is asserted as fact, not risk — Microsoft says devices were hit across seven sectors and that its automated containment fired mid-chain, which only happens where something real was running. But the footprint has no numbers on it: no device count, no organization count, no dwell time, no geographic breakdown beyond 'predominantly China-based operations and Chinese-speaking users'. A campaign confirmed to be landing, at an unknown scale.
Sober findings, promotional cure
Microsoft resists the obvious temptations: moderate confidence on the Silver Fox link, an explicit refusal to call it nation-state, and a warning not to blocklist shared hosting ASNs. The tilt comes from the frame around the findings — Defender detected and disrupted, then a list of Microsoft features to enable — which asserts more about the product's coverage than one vendor's own telemetry can establish. Meanwhile the finding that should reorder a defender's week, that hash indicators here expire after a single download, is left sitting in the delivery section.
The finder sells the fix
One party researched the campaign, named the threat, credited the save and wrote the remedy, and that party is Microsoft. The recommended controls are four Microsoft products; the detection story is Microsoft's own attack disruption; the telemetry field cited by name, FileOriginReferrerUrl, exists in Microsoft's schema. None of that makes the research wrong, and threat-intel publishing of this quality has a genuine defensive purpose. It does mean the reader has no way to test the parts that flatter the publisher against the parts that merely inform.
Trustworthy narrator, single vantage
We are fairly sure about the mechanism and much less sure about the magnitude. Server-side payload generation is the kind of thing endpoint telemetry is well placed to catch, the shared delivery path is corroborated across three brands inside the same dataset, and Microsoft's careful hedging where it is uncertain earns some credit. What holds the number down is that a second observer would change nothing about the story's internal consistency and everything about its verifiability — and that the scale, the timeline and the reach beyond Defender-monitored estates are simply not on the page.