03/09/2026
The download button is the whole intrusion in this one.
Microsoft published research on 1 September 2026 on an active campaign that builds convincing copies of vendor download pages, then serves a malicious installer to whoever clicks. The impersonated list includes Microsoft Edge, Kaspersky, draw.io and Calibre. Microsoft says the affected devices it observed sit predominantly in the China-based operations of multinational organisations and with Chinese-speaking users, in healthcare, manufacturing, logistics, government and higher education.
Once the file runs, it adds sweeping Microsoft Defender exclusions, deletes the volume shadow copies you would recover from, disables the Windows Update services, then hides its persistence in scheduled tasks with names that read like ordinary IT jobs.
Blocking the file does not work either. The archive keeps its name while the hash changes on every download, so there is nothing stable to put on a list.
The control that helps is Defender Tamper Protection, because it blocks those exclusion writes even when the malware is running as SYSTEM. Worth checking whether it is on across your fleet, and whether anyone would see the alert if it fired.