Counterfeit installers enable persistent system compromise
🛡️ Microsoft Defender Experts are tracking an active campaign that uses counterfeit software-download sites impersonating trusted vendors to distribute malicious installers. The campaign targets users seeking popular software and has caused compromises across multiple industries, with a concentration on China-based operations and Chinese-speaking users. The malicious installers establish persistence, evade defenses, and communicate with attacker infrastructure; Microsoft disrupted activity and recommends enabling protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
