# Bogus download sites deploy malware that disables Windows protections

_Wednesday, September 2, 2026 at 12:41 PM EDT · Security · Latest · Tier 1 — Major_

![Bogus download sites deploy malware that disables Windows protections — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhKCtgI2bIF4kLY71qjkluS80XAm5YPA9y9GzTxC8XBTaxq1d42jyZ-bxAr7OlZ-wCc4-RDp_NmUPKxd9TS1dvtjt3gysB86SkMuQ5q6vGb7HTh-DVMNC8VJcJFC2sJmiSQ740SX-miCoyiGfkAXLqO1ySH3zenWcAP7g6ilReO9jRsnl3Tnw279K7NYF3/s1700-nu-rw-lo-l85-e365/windows-updates.jpg)

Microsoft reported an active malware campaign using counterfeit software-download sites to distribute malicious installers, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. The malware establishes persistence, adds Microsoft Defender exclusions, disables Windows Update services, and contacts attacker-controlled infrastructure. Microsoft assessed with moderate confidence that the activity is consistent with the Silver Fox threat cluster and said automated containment was initiated through attack disruption.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/fake-software-installers-disable.html)

---
Canonical: https://techandbusiness.org/newswire/2RshZPFV85Qj4o-A0TJI4O
Retrieved: 2026-09-02T22:58:23.171Z
Publisher: Tech & Business (techandbusiness.org)
