Microsoft Threat Intelligence
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. https://msft.it/6011aTt3H Once executed, the malware payloads establish persistence through scheduled tasks, abuse trusted binaries, leverage a legitimate updater framework for payload delivery, inject code into legitimate processes, and communicate with command-and-control infrastructure over non-standard ports. Defenders should prioritize preventing downloads from untrusted sources and hunting for behavioral indicators rather than file names or hashes, which can rotate. Read the blog for an in-depth technical analysis, along with detection, mitigation, and hunting information.