Clever Malware Masquerades as Windows 11 Installer

Clever Malware Masquerades as Windows 11 Installer

Microsoft announced Windows 11 last year, but deploying the update to existing devices has been a slow process. In fact, Microsoft isn’t even providing the update on PCs that lack certain modern hardware features. Anyone who goes looking for a manual upgrade to Windows 11 might find themselves on the receiving end of a nasty malware attack, according to HP security researchers. A Russian website disguised as an official Microsoft page is distributing an “upgrade installer” that won’t get you Windows 11. What it will get you is a bunch of malware.

The site in question is windows-upgraded[.com], and we strongly suggest you don’t visit it (you probably won’tbe able to as it appears to be decommissioned). While reports suggest you will only encounter misfortune if you download files from this site, you don’t want to take any chances with these online criminals. The site is a dead ringer for Microsoft’s Windows Update site, and even the URL is a pretty good match—the hackers spent big on the .com domain.

Unlike the official website, the upgrade button downloads a ZIP archive hosted on Discord’s servers. This is something of an ongoing problem for the chat app, which has been used to distribute a surprising volume of malware in the past. When downloaded, the archive is just a few megabytes, consisting of an executable and several DLL files. The compressed archive hides the malware’s presence, and something strange happens when the user attempts to extract the files. The file size jumps to 735MB, most of which comes from the .EXE file. HP says the files are padded with 0x30 bytes of data that doesn’t have any bearing on the functionality. It’s just a trick to avoid detection by anti-malware tools, which are often incapable of automatically processing such a large file.

Clever Malware Masquerades as Windows 11 Installer

Absent any alarm bells, users will try to open the “upgrade” launcher, infecting their device with the RedLine Stealer malware. This piece of software is dangerous, but it’s not unique—online criminals can buy a copy of RedLine on hacking forums for $100-150. RedLine scrapes information from browsers, including form fill data, saved passwords, and credit card info. It can even steal any cryptocurrency stored on the device or in connected wallets. The researchers draw parallels between this attack and a December 2021 campaign that used a similar fake page that offered downloads of Discord’s desktop client. Instead, users got this same RedLine malware.

If you’re anxious to get Windows 11, make sure to only use the official Microsoft domain or the Windows settings menu. Downloading a random EXE from the internet continues to be a terrible idea.

Continue reading

Microsoft: Pluton Chip Will Bring Xbox-Like Security to Windows PCs
Microsoft: Pluton Chip Will Bring Xbox-Like Security to Windows PCs

Intel, AMD, and Qualcomm are working to make Pluton part of their upcoming designs, which should make PCs more difficult to hack, but it also bakes Microsoft technology into your hardware.

Apple: ‘It’s Up to Microsoft’ to Get Windows Running on New ARM Macs
Apple: ‘It’s Up to Microsoft’ to Get Windows Running on New ARM Macs

According to Apple, the question of supporting Windows on the M1 is entirely in Microsoft's court.

How Does Windows Use Multiple CPU Cores?
How Does Windows Use Multiple CPU Cores?

We take multi-core awareness for granted these days, but how do the CPU and operating system communicate with each other in the first place?

Minecraft With Ray Tracing Now Available for All Windows 10 Players
Minecraft With Ray Tracing Now Available for All Windows 10 Players

You don't usually think of Minecraft as a realistic game, but the developers have been hard at work adding RTX ray tracing to the game for the last eight months. It's finally out of beta today, and it really works with the blocky look of Minecraft.