Beware of fake Windows 11 updates being stolen by malware
Beware of fake Windows 11 updates. Missed immediately. Being stolen by malware.
Windows 11 always has a notorious reputation for updates, because it almost always comes with a new bug (Bug), but this time it goes even further because hackers have taken advantage of malware by using fake updates of Windows 11.
According to a report by the website, Techloy has mentioned the detection of an anonymous malware distribution campaign, but as a result of work, it is expected to be a malware type of theft from the victim or Infostealer by impersonating a Windows 11 24H2 update. The hacker will create a fake website that claims to be Microsoft's customer support page. The page tells the victim to install a Culmulative Update that is available for download under the file name WindowsUpdate 1.0.0. The file contains several data forgeries, such as changing the Metadata value to the same as the actual Microsoft file.
But when installed, it leads to a chain of running scripts and tools already on Windows. This step leads to placing malware files into the AppData folder and running with a running tool in Windows called cscript.exe. In later, the malware loads the fake Python environment to extract modules. These add-ons will continue to steal data. The goal of stealing data is to head to the data inside the web browser; and Messenger, a messaging platform whose type of data will cover both passwords (Passwords) saved on the browser, Authentication Cookies files, which involve identity confirmation; and Session files related to the use of various accounts. In addition to that, various information related to the use of the Discord chat application is also targeted.
The malware itself also creates persistence on the system by creating a Registry Entry called SecurityHealth, and then placing a Shortcut file in the Startup folder under the name Spotify .lnk to guarantee that the malware will be rebooted every time it is rebooted.
# Trending # Lemon 8 Howtoo # lemon 8 diary # windows 11 # freedomhack

























































































