Affected Systems

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. Campaign impersonates multiple legitimate software vendors (Razer, Microsoft Edge, Kaspersky, Calibre, DiskGenius, Baidu, and others) through spoofed .com.cn and .hl.cn domains delivering dynamically regenerated malicious installer archives.

Exploitation Status

Active exploitation confirmed. Microsoft Defender Experts is tracking ongoing campaign with confirmed compromises across multiple organizations and industries. Attack infrastructure actively serving dynamically generated payloads. Activity assessed with moderate confidence as consistent with Silver Fox (Yinhu) threat group. No nation-state attribution.

Business Impact

Successful compromise results in persistent malware installation that weakens security protections and establishes command-and-control communication. Primary risk to organizations with China-based operations or Chinese-speaking employees who may download software from impersonated vendor sites. Attack chain includes persistence mechanisms, privilege escalation, and defense evasion capabilities. Microsoft Defender XDR has detected and disrupted activity across multiple attack stages with automated containment.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Enable and enforce Microsoft Defender SmartScreen, network protection, and tamper protection to block downloads from untrusted sources and prevent security setting modifications
  • Block access to identified malicious domains using network security controls: gehie246[.]com, yimxg25tiy[.]com, cc8ttkv35b[.]com, n7b8t85zsg[.]com, and spoofed vendor domains listed in IOCs (pc-razerzone[.]com[.]cn, kaspersky-lab[.]hl[.]cn, calibre-ebook[.]com[.]cn, etc.)
  • Hunt for FileOriginReferrerUrl telemetry pointing to .com.cn and .hl.cn domains with embedded brand names, and investigate downloads of archives named app_setup.*, zinst.*, zintall.*, intsoft.*, innstll.* with changing hashes
  • Implement application control policies to prevent execution of installers downloaded from non-corporate sources, especially for China-based operations
  • Educate users, particularly Chinese-speaking staff, to download software only from official vendor websites and verify domain authenticity before downloading executables