[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-fake-download-sites-spoof-razer-kaspersky-to-plant-backdoors":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},6010,"fake-download-sites-spoof-razer-kaspersky-to-plant-backdoors","Fake Download Sites Spoof Razer, Kaspersky to Plant Backdoors","Microsoft says a Chinese group is spoofing brands like Razer and Kaspersky to install backdoors that weaken, not disable, Windows Defender.","A Chinese hacking group is running fake download pages for some of the most recognizable names in software to slip backdoors onto victims' machines.\n\nMicrosoft says the group, tracked as Silver Fox (also known as Yinhu), built lookalike download sites for brands including Razer, Kaspersky, NetEase, Baidu NetDisk, SteelSeries, Calibre, and MindMaster. Anyone who grabs the \"installer\" actually gets a backdoored version that sets up scheduled tasks for persistence and injects itself into legitimate processes. Once in, the malware weakens Windows Defender's oversight by creating a broad exclusion folder that keeps its own files out of scanning range and by disabling several Windows Update services; it doesn't switch Defender off outright, it just blinds it in the places that matter. From there, the backdoor deletes backups and opens the door for further payloads.\n\nThis isn't a niche stunt. Microsoft found victims across healthcare, manufacturing, gaming, government, and higher education, mostly in China but spreading wider. The exclusion-folder trick is the real story: it's a reminder that \"antivirus is running\" and \"antivirus is actually watching your files\" are two different claims, and attackers keep exploiting the gap between them.\n\nMicrosoft's fix is blunt but telling: turn on tamper protection so Defender's settings can't be quietly rewritten, even by something running as SYSTEM, and stop trusting a file by its name alone.","[\"malware\",\"silver-fox\",\"windows-defender\",\"brand-spoofing\"]","2026-09-02T16:50:00.000Z","2026-09-02T18:03:46.026Z","2026-09-02T18:03:57.221Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"publisher-r1","publisher",1,"The article says Silver Fox 'disables Windows Defender' in the dek and body, but the body also says it 'creates a large Defender exclusion folder' and Microsoft's advice is to 'enforce tamper protection' — these details are inconsistent about whether Defender is disabled outright or merely evaded via exclusions, which is a factual coherence issue that needs clarification before publishing.","resolved","security",[32,33,34,35],"malware","silver-fox","windows-defender","brand-spoofing",[37],{"name":38,"url":39},"TechRadar","https:\u002F\u002Fwww.techradar.com\u002Fpro\u002Fsecurity\u002Fa-malware-installer-posing-as-a-legitimate-download-service-is-infecting-brands-across-almost-every-industry-microsoft-edge-razer-kaspersky-and-more-actively-imitated",0,{"sections":42},[43,48,52,57,62,67,72,77,82,87,92,97,102,107],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3385,"2026-09-04T22:17:36.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":51},"Security",565,"2026-09-05T00:03:08.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Policy","policy",300,"2026-09-04T22:18:34.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":61},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":63,"slug":64,"count":65,"latest_published_at":66},"Hardware","hardware",152,"2026-09-03T09:26:48.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Consumer Tech","consumer-tech",97,"2026-09-04T15:29:18.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":76},"Science","science",96,"2026-09-03T22:30:00.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",54,"2026-09-04T23:36:14.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"General","general",37,"2026-09-04T20:22:41.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]