Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Scheduled Pinned Locked Moved Malware Analysis
microsoft
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    An active malware campaign is being distributed through bogus software-download websites that impersonate trusted vendors, luring victims with malicious installers. According to Microsoft, the campaign has resulted in compromises across multiple organizations and industries, with a primary focus on China-based operations of multinational companies and Chinese-speaking users.

    The attackers are using trojanized installers that go beyond simple payload delivery. Once executed, the malware actively disables Windows Update and tampers with Microsoft Defender, weakening the host’s defenses to avoid detection and maintain persistence. This dual-action approach allows the threat to operate with fewer safeguards in place, increasing the risk of lateral movement and data exfiltration.

    Key technical observations from the campaign include:

    • Malicious installers are hosted on fake download portals that mimic legitimate vendor sites.
    • The malware modifies system settings to stop Windows Update from running, preventing critical patches from being applied.
    • Microsoft Defender is altered or disabled, reducing endpoint visibility and allowing the payload to execute more freely.
    • The campaign appears to be geographically targeted, with a concentration on Chinese-speaking users and multinational organizations operating in China.

    Organizations should review their endpoint detection and response logs for signs of disabled security services or failed update attempts. Users are advised to avoid downloading software from unofficial or unverified mirrors, and to verify the authenticity of any installer before execution.

    Source: The Hacker News

    Are any of your endpoints showing signs of disabled update services or modified Defender policies, and how are you tracking this campaign across your environment?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World