
Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.
“Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,” Microsoft security researchers wrote in a blog post.
The campaign, tracked by Microsoft Defender Experts, has impacted organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education, the company said.
