Threat Intelligence

Fake Software Download Sites Used to Disable Windows Security Defences

The Hacker News · 3 Sept 2026
Key Takeaway Only download software from official vendor websites or verified app stores, and set policies restricting employees from installing unauthorised applications.

Researchers have identified an active malware campaign that lures users into downloading fake software installers from websites impersonating well-known vendors. Once installed, the malicious software disables Windows Update and weakens Microsoft Defender, reducing the victim's ability to detect and patch against further attacks. Microsoft reports the campaign has already led to compromises across multiple organisations and industries, with a primary focus on China-based operations of multinational companies and Chinese-speaking users.

By targeting the software download process itself, attackers exploit a common and often unmonitored entry point—employees searching online for tools or applications and downloading them from unofficial or spoofed sites. Once security defences like Defender and Windows Update are disabled, attackers can operate with far less resistance, potentially installing further malware, stealing data, or maintaining long-term access to compromised systems.

While this campaign currently appears concentrated in specific regions, the tactic of hiding malware inside fake installers is common globally and could easily be adapted to target other markets, including Australian businesses. Organisations should be alert to any unexpected changes in security settings, unfamiliar software installations, or unauthorised disabling of update and protection services.

malware fake installers Windows Defender Windows Update supply chain security
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.