← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 22:48via Microsoft Security Blog

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Brief

In this article

  • Attack chain overview
  • Campaign scope and targeting
  • Mitigation and protection guidance
  • References
  • Learn more

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. Microsoft has observed victims across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure.

Read more on Microsoft Security Blog