Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.
The fake Razer/Edge/Kaspersky installer was a regenerated ZIP, not a one-hash IOC
Microsoft Defender Experts tracked look-alike .com.cn download pages, Aliyun staging, and six-character .net C2 — moderate confidence overlap with Silver Fox / Yinhu, not a nation-state call.
Bottom line up front
CONFIRMED 1 September 2026 Microsoft — active campaign of counterfeit vendor download sites (Razer, Microsoft Edge, Kaspersky look-alikes on .com.cn / .hl.cn), delivery hosts such as gehie246[.]com, Aliyun OSS staging, persistence, Defender exclusions, shadow-copy delete, Windows Update disable, C2 to six-character .net domains and a listed IP:port set. Victims: China-based ops of multinationals and Chinese-speaking users; healthcare, manufacturing, gaming, technology, logistics, government, education observed. Microsoft: moderate confidence consistent with public Silver Fox (Yinhu) fake-software reporting; not attributed as a nation-state. Telemetry: same-named ZIP regenerated with different content ~69 seconds apart — hash IOCs rot on purpose.
Historical backfill of 1 September 2026 reporting; added 7 September 2026.
What happened
SEO/typosquat download. User runs setup. Box is owned. Adjacent to fake-VPN and fake-AI-brand lures already in this archive; different infra and date.
Why it mattered
Allow-listing "we only download from vendor.com" fails when Google's first result is vendor.com.cn. Server-side regeneration defeats yesterday's hash.
Who / what was affected
Sectors above, China-centric targeting in Microsoft's set.
Technical context
Hunt the published C2 IPs/ports and .net names; scheduled tasks from Public/ProgramData; MpPreference exclusions. Prefer publisher-authenticode plus known download URLs.
Exploitation / threat status at the time
CONFIRMED Microsoft campaign and IOCs.
ASSESSED (moderate, Microsoft): Silver Fox overlap.
What defenders should have done
- Block the lure domains and delivery paths.
- Software packaging via Intune/winget, not search.
- Assume unique hashes per download.
RWP assessment
Confidence: High on the campaign sketch. Search-bar software is initial access.
Defensive actions
- DNS sinkhole listed lures.
- Alert on Defender exclusion changes.
- User rule: never install Razer/Edge/AV from an ad.
Sources
- Microsoft Defender Experts — Counterfeit installers to system compromise
- Microsoft — AI brands as bait
- Microsoft — Storm-2561 SEO fake VPN