Fake installer campaign: Microsoft reports malware threats
An active campaign uses counterfeit download pages and fake software installers to spread malware and compromise corporate systems.

Microsoft has identified an active malicious campaign that exploits the identity of legitimate software vendors to deceive users. Cybercriminals are using counterfeit download pages, created to look completely identical to the original ones, and repackaged installation archives to distribute malware and compromise computer systems.
To help organizations identify, block, and respond effectively to this threat, Microsoft Defender experts have shared a detailed analysis. The observed attack techniques, detections via Defender XDR, indicators of compromise, and a series of practical mitigation measures have been made public.
The recommendation for companies is to pay the utmost attention to the sources from which programs are downloaded, monitoring their systems to promptly detect any anomalies linked to this specific distribution campaign.
