New Threat: Malware Poses as Windows 11 Update to Steal Your Data
Cybersecurity researchers warn of a sophisticated campaign tricking users with a fake operating system patch. This malicious program aims to steal sensitive information.

A new cyberattack campaign is endangering Windows 11 users. Sophisticated malware disguises itself as an official operating system update. Malwarebytes researchers detected this active threat. Its primary goal is to steal passwords, banking data, and access credentials. Staying vigilant against this new deception method is crucial.
The deception begins on a fraudulent website. It closely mimics Microsoft's support portal. This site offers a fake update for Windows 11 version “24H2”. The page promotes a supposed “cumulative update” with a technical article number. It includes a convincing description of performance improvements and security patches. A large blue button invites users to download the “WindowsUpdate 1.0.0.msi” file.
The installer is 83 MB and was created using WiX Toolset. This is a legitimate tool for packaging Windows programs. Its properties were altered to appear authentic. The file lists Microsoft as the developer. It contains descriptions similar to an official installer. This reduces suspicion for many users.
Once executed, the malware begins collecting information from the infected computer. First, it obtains the device's public IP address. It also records its approximate location. Then, it installs several hidden components. These components allow access to data saved in the browser.
The malicious program steals passwords, session cookies, and payment methods. It even extracts information from Discord accounts. Researchers explain its operation. It uses Python packages and hidden code within JavaScript files. These functions encrypt the stolen information. They then send it to a server controlled by the attackers.
The malware can modify installed applications. For example, it alters Discord to intercept access tokens. It also captures password changes and two-factor authentication data.
One of the most concerning aspects is its evasion capability. The threat managed to go undetected by security tools.This happens because the executable appears legitimate. The malicious behavior hides within highly obfuscated JavaScript code. Many antivirus programs do not thoroughly check this layer.
To remain active even after restarting the computer, the malware employs two persistence mechanisms.
- It modifies the Windows registry. It creates an entry named “SecurityHealth”. This name mimics Windows' security notification system.
- It adds a shortcut called “Spotify.lnk” to the startup folder. This ensures the malicious program runs every time the computer starts.
Keep reading online — scan the code
https://go.tricuatro.com/ZCBWF
© tricuatro.com
Article topics
Related articles

MIT Chip Converts Invisible Infrared Light into Crucial Data
MIT researchers developed an innovative chip detecting methane and propane using mid-infrared light, with potential for millions of pixels and optical computing.

Tesla Launches Electric Cybertruck Replica for Kids in the US
Tesla introduces its scaled-down Cybertruck for children aged 6 to 12, an electric vehicle priced at USD 1,500, currently exclusive to the US market.

Samsung Galaxy Z Fold 8: "Passport" Design and Specs Leaked
Samsung's upcoming foldable, the Galaxy Z Fold 8, has been fully leaked, revealing a more square design and details on its displays, processor, and battery ahead of its official July launch.
Latest news
View all
Sweet Interstellar Discovery: Erythrulose Detected in the Milky Way
Scientists from the Spanish Astrobiology Center have for the first time identified a true sugar, erythrulose, in a gas and dust cloud near our galaxy's center. This finding suggests complex molecules can form before stars and planets are born.

Paramount and Warner Bros. Merger Halted by Judge Over Antitrust Concerns
A coalition of 12 states successfully petitioned Judge Araceli Martinez-Olguin to temporarily block the deal, citing fears of higher prices and reduced content.

Assassin's Creed Black Flag Resynced Smashes 3 Million Sales, New Game Plus Announced
Ubisoft's successful re-release of the pirate classic continues to break records, confirming one of the most requested features from the gaming community.
Comments (0)
No comments yet. Be the first!
Only registered readers can comment.