An active campaign uses fake download sites—clones of software manufacturers' websites—to distribute installers that disable Windows Update and weaken Microsoft Defender.
Microsoft documented the attack in early September 2026. The websites are highly realistic copies of pages from well-known manufacturers, featuring a prominent “Download” button. The downloaded file looks like a regular installer, but once launched, it installs malicious software on the computer.
What this program does is the truly dangerous part. It ensures it starts automatically through scheduled tasks disguised as routine IT activities, then adds exceptions to Microsoft Defender Antivirus so it won’t be detected. It stops and disables Windows Update services so the system remains unpatched, and deletes the hidden copies that Windows uses for recovery—making it impossible to restore files locally. Finally, it opens a hidden connection to the attackers’ infrastructure.
The current wave has primarily affected operations and users in Asia, but the method is not specific to any one region. Clone pages promoted through ads and sponsored search results are one of the most common ways for malware to enter a company, and the group behind the campaign has used this pattern in the past as well.
For a small business, defense is more about discipline than about an expensive product. The measures that matter:
- Download software only from the manufacturer's official website, either by typing the URL directly into your browser or by accessing it from a saved bookmark—never from an ad or a sponsored search result;
- a short list of approved sources and programs, plus restricted administrator privileges, so employees cannot install just anything;
- offline backups, tested periodically—because an attack deletes local recovery copies;
- treating it as a warning sign when Windows Update or your antivirus suddenly stops working, rather than attributing it to a glitch.
Verifying the sources from which software is installed and limiting administrator privileges are simple organizational measures that are part of a company’s cybersecurity obligations. We can implement them together.
Sources:
This article was generated with AI assistance.