Contacts
Follow us:
Contact us
Close

CONTACTS

Krikis, MB, Company code: 305601196, Klaipėda, Lithuania

info@krikis.lt

Creative installer-induced system corruption: how to recognize a fraudulent software download campaign

Creative installer-induced system corruption: how to recognize a fraudulent software download campaign

Creative installer-induced system corruption: how to recognize a fraudulent software download campaign

Microsoft Defender Experts recently began monitoring an active malware campaign using fake application download sites. These sites pretend to be trusted vendors and their goal is to distribute malicious installation packages. The campaign targets users searching for popular software and has already resulted in breaches across organizations and industries, particularly in China operations centers and among Chinese-speaking users.

Observations indicate that the affected industries include healthcare, manufacturing, gaming, technology, logistics, government, and higher education. The incidents are most likely related to devices with IP addresses or domains ending in .com.cn, .hl.cn, and .cn, indicating that the fraudulent websites are leveraging Chinese language content and local infrastructure. In one specific example, a user browsing the fake Razer page pc-razerzone[.]com[.]cn downloaded „app_setup.6653004.zip“ from the delivery server gehie246[.]com/712down. This download was observed to create two different archive copies within 69 seconds, indicating that the malware is generating packets on the server side for each request.

How the fraudulent installation chain works

Artificial Intelligence Data Center

The campaign follows a sequential chain of attacks: from initial access to event execution, persistence, privilege escalation, defense bypass, and command-line manipulation. The first step is to create a deceptive website page that mirrors the vendor’s real design and logo. When the user clicks the „Download now“ button, the browser (usually Microsoft Edge) directs the request to a small but consistent set of servers that host malicious archives. These archives have a consistent file name (e.g. app_setup., science., intsoft.*), but their hash values change every time they are downloaded - a strong indicator that the content is dynamically generated.

Once downloaded, the malicious installation package installs a persistent implant that creates persistence mechanisms, weakens security defenses, and establishes communication with the attack controller's infrastructure. Microsoft observed that some devices are communicating with a suspected Alibaba Cloud Object Storage Service (OSS) bucket that acts as a command and control (C2) point.

Identification features and technical indicators

Microsoft Defender has provided several specific indicators to help identify this threat:

  • Domain names that mimic the names of well-known brands and end in .com.cn, .hl.cn, or .cn.
  • Persistent file names with changing hashes that indicate server-side packet regeneration.
  • Identical download URLs, such as yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst, n7b8t85zsg[.]com/ins711, which point to the same delivery infrastructure.
  • Telemetry data displayed via FileOriginReferrerUrl, which links the downloaded archive to a fraudulent upload page.
  • Infrastructure grouping: Six domain groups are in AS132839, divided into four invalid network blocks and three country codes, sharing common name servers; the other two domain groups are in AS8796, using another pair of name servers.

Prevention measures

Business Technology Office

Microsoft recommends several basic layers of security that can help organizations protect themselves from this type of attack:

  • SmartScreen – enable this browser feature that filters known malicious URLs and warns users before downloading.
  • Network protection – block access to known malicious domains directly from the network level.
  • Tamper protection – protect Microsoft Defender configuration from unauthorized changes.
  • Microsoft Defender XDR – use an advanced threat detection and response solution that can automatically isolate suspicious devices and stop malicious activity.

Additionally, it is important to educate employees about the risks of downloading software from untrusted sources, checking URLs before clicking, and using official vendor websites.

Conclusions

Fraudulent app installation campaigns, as documented in the Microsoft Defender study, demonstrate that cyberthreat tactics are becoming increasingly automated and targeted at specific linguistic and geographic audiences. While these attacks are most commonly targeted at Chinese-speaking users, their structure and methods can be adapted to any market. Therefore, organizations should consistently apply technical protections and encourage safe behaviors to reduce the risk of „software download security“ breaches.

Sources

IT SERVICES

Let's transform technology real results for your business.

We help companies apply artificial intelligence, automation, internet systems, and other digital solutions to real business processes.

Contact us Initial consultation is free of charge.