Fake Software Download Sites Push Malware That Turns Off Windows Update

Microsoft says a long-running campaign is pushing rigged installers to Chinese-speaking users and staff at multinationals operating in China, disabling defences on the way in.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dimly lit government office at night in Southeast Asia, empty desk with a glowing monitor showing abstract green code
Share

Key points

  • Microsoft's threat intelligence team is tracking an active campaign that uses fake software download sites to trick people into installing malware.
  • The campaign mainly hits Chinese-speaking users and the China-based offices of multinational companies, across several industries.
  • The rigged installers switch off Windows Update and weaken Microsoft Defender, the built-in antivirus, so the infection can stay hidden.
  • Victims think they are downloading well-known software from a trusted vendor's site.
  • Microsoft has not publicly tied the activity to a named group, and the reporting so far rests on a single vendor's telemetry.

Microsoft is warning about a malware operation that hides behind fake versions of popular software download pages. People searching for a familiar app land on a lookalike site, click download, and install malware instead.

The campaign was flagged in Microsoft's own threat intelligence write-up and picked up by The Hacker News. It is aimed mostly at Chinese-speaking users and at staff working in the China-based operations of large multinational firms.

That targeting matters. It shapes who is at risk today and hints at what the operators are after, though Microsoft has not spelled out a motive.

How does the attack actually work?

Someone searches for a common bit of software and clicks a result that looks like the real vendor's page. The site is a copy. The installer they download is booby-trapped: it may install the app they wanted, but it also drops malware in the background.

The installer then goes after the machine's defences. It disables Windows Update, the service that delivers security patches from Microsoft. It also tampers with Microsoft Defender, the antivirus built into Windows, weakening its ability to spot or remove what has just landed.

With patches blocked and the antivirus hobbled, the intruders have room to work. That could mean stealing credentials, planting more tools, or quietly staying on the machine for months.

Who is behind it?

Microsoft has not attributed the activity to a named cluster, and no other vendor has publicly corroborated it yet. That puts confidence in any attribution at low for now.

The targeting profile, Chinese-speaking users and multinationals' China offices, is consistent with several known China-nexus espionage clusters (Mustang Panda, tracked by CrowdStrike; Silk Typhoon in Microsoft's newer weather-themed naming). It is also consistent with plain financially motivated crews that seed poisoned installers to harvest anything valuable. Capability here is not the same as intent. Without shared infrastructure or malware families being called out, it is safer to treat this as an unattributed campaign with overlapping TTPs to several groups.

Fake installer lures are not new. Groups tracked as FIN7, Nitrogen and various loader crews have all used them. That makes the technique noisy and hard to pin on any one operator from behaviour alone.

What should ordinary users do?

Stick to the vendor's real website. If you searched for a program and clicked a sponsored or top result, check the web address carefully before you download anything. Small spelling changes are the whole trick.

If Windows Update suddenly stops working, or Microsoft Defender turns itself off and will not turn back on, treat that as a red flag rather than an annoyance. Both are classic signs that something on the machine is fighting the defences.

Detail What Microsoft has said
Delivery Fake software download websites impersonating trusted vendors
Main targets Chinese-speaking users; China-based operations of multinationals
Impact on defences Disables Windows Update, weakens Microsoft Defender
Named group None publicly attributed
Confidence Single-vendor reporting, medium confidence in scope

For company IT teams, the useful signal is not the lure itself but the tampering. Alerts on Defender being disabled, tamper protection being switched off, or Windows Update services being stopped will catch this class of intrusion regardless of which installer delivered it.

© 2026 Threat Vectr