Attackers are using spoofed websites impersonating Microsoft Edge, Kaspersky, Razer and other vendors to distribute trojanized installers that establish persistence and weaken security defenses.