An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system

A new report details an active campaign leveraging counterfeit software installers to achieve system compromise. The campaign reportedly impersonates legitimate software vendors, employing look-alike download pages and regenerated installer archives to distribute malware. Microsoft Defender Experts has shared observations regarding the attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to assist organizations in identifying, blocking, and responding to this ongoing threat.
The core mechanism of this campaign involves social engineering users into downloading malicious software. Attackers create deceptive download pages that closely mimic those of legitimate software vendors. These pages host installer archives that, while appearing authentic, have been tampered with to include malware. When a user downloads and executes one of these counterfeit installers, they inadvertently initiate the infection process, leading to system compromise.
Products in the category of endpoint detection and response (EDR) and extended detection and response (XDR) are typically designed to identify and flag suspicious activity associated with such campaigns. This includes detecting unusual file modifications, unexpected process executions, and network communications to known malicious infrastructure. The report from Microsoft Defender Experts specifically highlights Defender XDR detections, suggesting that organizations utilizing Microsoft's security suite may have built-in capabilities to identify elements of this threat.
The likely scope of such a campaign is broad, as it preys on common user behavior of seeking out and downloading software from the internet. Any organization whose employees download software, even from seemingly reputable sources, could potentially be targeted. The effectiveness of the campaign hinges on the attackers' ability to maintain convincing impersonations and evade detection by standard security measures.
Mitigation guidance for this class of issue typically emphasizes a multi-layered approach. This includes user education to recognize phishing attempts and suspicious download sources, the implementation of strong email and web filtering to block access to malicious sites, and the use of application whitelisting or strict software installation policies to prevent unauthorized software from running. Regular patching and updates of operating systems and security software are also crucial.
Organizations are advised to review the provided indicators of compromise (IoCs) to proactively scan their networks for any signs of infection. Furthermore, strengthening endpoint security configurations, enforcing least privilege principles, and conducting regular security awareness training for employees can significantly reduce the risk posed by such deceptive software download campaigns. This incident underscores the persistent challenge of supply chain attacks and the need for continuous vigilance against evolving social engineering tactics.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.