Microsoft is tracking an active fake software campaign that regenerates malicious archives behind familiar download filenames, then uses Windows components such as `msiexec.exe` to execute payloads from randomized public directories. The Silver Fox-linked activity has compromised organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, particularly those with China-based operations or Chinese-speaking users.
Source