Fake Software Download Sites Used to Disable Windows Security Defences
Researchers have identified an active malware campaign that lures users into downloading fake software installers from websites impersonating well-known vendors. Once installed, the malicious software disables Windows Update and weakens Microsoft Defender, reducing the victim's ability to detect and patch against further attacks. Microsoft reports the campaign has already led to compromises across multiple organisations and industries, with a primary focus on China-based operations of multinational companies and Chinese-speaking users.
By targeting the software download process itself, attackers exploit a common and often unmonitored entry point—employees searching online for tools or applications and downloading them from unofficial or spoofed sites. Once security defences like Defender and Windows Update are disabled, attackers can operate with far less resistance, potentially installing further malware, stealing data, or maintaining long-term access to compromised systems.
While this campaign currently appears concentrated in specific regions, the tactic of hiding malware inside fake installers is common globally and could easily be adapted to target other markets, including Australian businesses. Organisations should be alert to any unexpected changes in security settings, unfamiliar software installations, or unauthorised disabling of update and protection services.