A Chinese hacking group is running fake download pages for some of the most recognizable names in software to slip backdoors onto victims' machines.
Microsoft says the group, tracked as Silver Fox (also known as Yinhu), built lookalike download sites for brands including Razer, Kaspersky, NetEase, Baidu NetDisk, SteelSeries, Calibre, and MindMaster. Anyone who grabs the "installer" actually gets a backdoored version that sets up scheduled tasks for persistence and injects itself into legitimate processes. Once in, the malware weakens Windows Defender's oversight by creating a broad exclusion folder that keeps its own files out of scanning range and by disabling several Windows Update services; it doesn't switch Defender off outright, it just blinds it in the places that matter. From there, the backdoor deletes backups and opens the door for further payloads.
This isn't a niche stunt. Microsoft found victims across healthcare, manufacturing, gaming, government, and higher education, mostly in China but spreading wider. The exclusion-folder trick is the real story: it's a reminder that "antivirus is running" and "antivirus is actually watching your files" are two different claims, and attackers keep exploiting the gap between them.
Microsoft's fix is blunt but telling: turn on tamper protection so Defender's settings can't be quietly rewritten, even by something running as SYSTEM, and stop trusting a file by its name alone.