Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Multinational organizations with China-based operations
Incident: Distribution of malware via spoofed software download pages.
Impact: Complete disablement of core OS security updates and endpoint protection.
Attacker: Silver Fox (Yinhu)
Analysis: The campaign utilizes server-side payload generation to evade hash-based detection and deploys malware via spoofed vendor pages. Once executed, the malware systematically disables Windows Update and Microsoft Defender while establishing persistence through scheduled tasks. By modifying DACLs and deleting volume shadow copies, the attackers ensure the payload remains hidden and difficult to remove.
Recommendations: Implement strict DNS filtering to block malicious .cn infrastructure and known C2 domains.; Educate users to verify software sources and avoid third-party download mirrors.; Monitor for unauthorized modifications to Windows Update services and unexpected Microsoft Defender exclusions.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source