"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft said.
Microsoft links activity to Silver Fox (aka Yinhu)
Microsoft attributed the campaign with moderate confidence to a Chinese threat cluster it calls Silver Fox, also known as Yinhu. The vendor said the activity is consistent with Silver Fox's prior use of spoofed vendor download pages to distribute families such as Gh0st RAT and ValleyRAT (aka WinOS 4.0). Victims span healthcare, manufacturing, gaming, technology, logistics, government and education sectors, with the bulk of compromise activity affecting China-based operations of multinational organizations and Chinese-speaking users.
Spoofed vendor sites, server-side payloads and observed domains
The attackers used high-fidelity clones of legitimate vendor sites hosted on .com.cn and .hl.cn infrastructure and delivered a Chinese-language lure that triggers a ZIP archive download from gehie246[.]com. Microsoft notes the downloaded archive keeps the same file name while the file hash changes on every download, indicating the payload is generated server-side per request.
- Observed counterfeit domains included app-microsoft-edge[.]com[.]cn, baidu-pan[.]com[.]cn, calibre-ebook[.]com[.]cn, cn-drawio[.]com[.]cn, gw-sogou[.]com[.]cn, kaspersky-lab[.]hl[.]cn, mindmoster[.]com[.]cn, ocam-pc[.]com[.]cn, pc-razerzone[.]com[.]cn, sejda[.]hl[.]cn, steelseries-cn[.]com[.]cn, translate-youdao[.]hl[.]cn and zh-diskgenius[.]com[.]cn.
- Two command-and-control domains Microsoft linked to the activity are iualef[.]net and oijfwe[.]net.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageInstaller chain, persistence and system tampering
Once the ZIP archive is opened, victims encounter a wrapper installer (for example, "a_instapp83353001.exe" or "ainst8663586104.exe") that launches a first‑stage payload. Microsoft also observed a second vector that abuses the trusted Windows Installer service (msiexec.exe) to launch a randomized executable while preserving the same masquerade pattern as the wrapper chain.
Persistence is achieved through scheduled tasks that mimic routine IT or productivity jobs. The malware creates a short-lived scheduled task that runs as SYSTEM and uses PowerShell to configure Microsoft Defender exclusions. It also deletes volume shadow copies, modifies discretionary access control lists (DACLs) on payload directories via icacls to prevent removal by standard users, and establishes C2 communications over application-layer protocols on non-standard ports including 5090, 7031, 7032, 7088–7090, 8050, 28290 and 28300.
Tampering with Windows Update and weakening Defender
Microsoft reported the malicious chain actively interferes with Windows Update and related services: it stops and disables wuauserv, UsoSvc, uhssvc and WaaSMedicSvc, renames update DLLs and deletes the SoftwareDistribution cache. By running PowerShell to add Defender exclusions and arranging tasks that operate as SYSTEM, the malware weakens endpoint defenses and makes automated remediation and manual removal more difficult.
Microsoft also said Defender detected the activity and initiated automated containment procedures through attack disruption to limit impact, although the company described the overall campaign objective as unclear.
Related findings: ValleyRAT, Gh0st RAT, QN Wallpaper and other connections
Kaspersky separately described an installer that delivers a modified version of a Chinese desktop wallpaper management tool called QN Wallpaper; attackers used it to execute a DLL sideloading chain that delivered ValleyRAT. Kaspersky noted the original QN Wallpaper is genuine adware that bundles partner apps and displays ads, but in the observed attacks it was repurposed to run a backdoor under the guise of a signed process.
ValleyRAT, as described by Kaspersky, protects its process from termination, captures keystrokes and clipboard contents and writes those logs to disk; it periodically scans for windows belonging to analysis tools, can collect system information, reboot or shut down the host, take screenshots, wipe logs, update C2 addresses, and download additional DLL or shellcode modules. Expel reported that ValleyRAT use has been attributed to a subgroup within GoldenEyeDog called CuboidalCanine, which reportedly moved away from Gh0st RAT at some point and has targeted the gambling industry using watering holes and abused code-signing certificates. Security researcher Aaron Walton observed that "this malware isn't unique to any actor" and that attribution often relies on factors beyond the malware family itself.
What this means for Chinese-speaking users, security teams, and affected enterprises
- Chinese-speaking users and China-based operations of multinational organizations: the campaign used Chinese‑language lure content and domains on .com.cn/.hl.cn infrastructure, making these populations central targets; they were the primary demographic Microsoft highlighted as affected.
- Security teams and technologists: indicators in this activity include server‑side generated payloads that change hash per download, wrapper installer names like a_instapp*.exe, abuse of msiexec.exe, scheduled tasks running as SYSTEM, PowerShell‑driven Defender exclusions, DACL modifications via icacls, Windows Update service stoppage and deletion of SoftwareDistribution, and C2 traffic on non‑standard application‑layer ports and the domains iualef[.]net and oijfwe[.]net.
- Affected enterprises across healthcare, manufacturing, gaming, technology, logistics, government and education: Microsoft reported compromises across these sectors, underscoring that the campaign has a broad cross‑sector impact rather than a single vertical focus.
Microsoft's assessment ties this campaign to a pattern of using spoofed vendor download pages and repurposed legitimate applications to deliver backdoors. Kaspersky and Expel reporting on ValleyRAT, Gh0st RAT and related tactics underscores a recurring convergence of supply‑style deception and DLL sideloading. The attack's immediate aim remains unclear, but the techniques—disabling update services, weakening Defender, and using server‑generated payloads—paint a picture of intrusions designed for resilience and stealth. In June 2026, China Daily reported Chinese authorities had taken action against cases distributing a new Silver Fox variant, a further signal that elements of this activity have attracted law‑enforcement attention.




