Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.

Daily Top · Malware

The fake Razer/Edge/Kaspersky installer was a regenerated ZIP, not a one-hash IOC

Microsoft Defender Experts tracked look-alike .com.cn download pages, Aliyun staging, and six-character .net C2 — moderate confidence overlap with Silver Fox / Yinhu, not a nation-state call.

RWP Ventures · 2026-09-07 · event 2026-09-01 · 1 min read · priority 7.8

Bottom line up front

CONFIRMED 1 September 2026 Microsoft — active campaign of counterfeit vendor download sites (Razer, Microsoft Edge, Kaspersky look-alikes on .com.cn / .hl.cn), delivery hosts such as gehie246[.]com, Aliyun OSS staging, persistence, Defender exclusions, shadow-copy delete, Windows Update disable, C2 to six-character .net domains and a listed IP:port set. Victims: China-based ops of multinationals and Chinese-speaking users; healthcare, manufacturing, gaming, technology, logistics, government, education observed. Microsoft: moderate confidence consistent with public Silver Fox (Yinhu) fake-software reporting; not attributed as a nation-state. Telemetry: same-named ZIP regenerated with different content ~69 seconds apart — hash IOCs rot on purpose.

Historical backfill of 1 September 2026 reporting; added 7 September 2026.

What happened

SEO/typosquat download. User runs setup. Box is owned. Adjacent to fake-VPN and fake-AI-brand lures already in this archive; different infra and date.

Why it mattered

Allow-listing "we only download from vendor.com" fails when Google's first result is vendor.com.cn. Server-side regeneration defeats yesterday's hash.

Who / what was affected

Sectors above, China-centric targeting in Microsoft's set.

Technical context

Hunt the published C2 IPs/ports and .net names; scheduled tasks from Public/ProgramData; MpPreference exclusions. Prefer publisher-authenticode plus known download URLs.

Exploitation / threat status at the time

CONFIRMED Microsoft campaign and IOCs.

ASSESSED (moderate, Microsoft): Silver Fox overlap.

What defenders should have done

  1. Block the lure domains and delivery paths.
  2. Software packaging via Intune/winget, not search.
  3. Assume unique hashes per download.

RWP assessment

Confidence: High on the campaign sketch. Search-bar software is initial access.

Defensive actions

  1. DNS sinkhole listed lures.
  2. Alert on Defender exclusion changes.
  3. User rule: never install Razer/Edge/AV from an ad.

Sources

  1. Microsoft Defender Experts — Counterfeit installers to system compromise
  2. Microsoft — AI brands as bait
  3. Microsoft — Storm-2561 SEO fake VPN