Drooid Logo
Back to story perspectives

Full Breakdown

Fake Windows 11 24H2 Update Campaign Poses Security Risks

4/16/2026, 1:04:37 AM

Overview of the Threat

Security researchers at Malwarebytes have identified a malicious campaign that exploits a fake Windows 11 24H2 update to steal sensitive data from users. The attackers have created a convincing Microsoft-style support page hosted on a typosquatted domain, "microsoft-update[.]support," which encourages users to download what appears to be a legitimate cumulative update for Windows 11.

How the Malware Operates

The deceptive download, labeled "WindowsUpdate 1.0.0.msi," employs legitimate packaging tools and spoofed Microsoft metadata to appear authentic. Upon execution, the installer sets up an Electron-based application in the user's AppData folder and launches it via a script utilizing Windows' cscript.exe tool. This process initiates a renamed Python interpreter that loads additional modules designed to extract sensitive information, including browser-stored passwords, cookies, and Discord data. The malware then transmits this data to servers controlled by the attackers.

Evasion of Security Measures

The malware's architecture is sophisticated enough to evade detection by common antivirus solutions. Early samples reportedly showed zero detections on VirusTotal, with 69 engines failing to identify the main executable and 62 missing the VBS launcher. The malware's use of the WiX Toolset, a legitimate open-source installer framework, allows it to masquerade as a benign application, complicating detection efforts.

Official Recommendations

Experts advise users to download Windows updates exclusively from the Windows Update settings menu or official Microsoft domains. Malwarebytes emphasizes the importance of vigilance, stating that the fake update campaign is difficult to distinguish from legitimate updates. Users who may have installed the fake update are urged to remove the associated files and registry entries, conduct a full malware scan, and change passwords for any accounts stored on the affected PC.

Criticism & Opposition

While the campaign highlights the growing sophistication of cyber threats, it also raises concerns about the effectiveness of current security measures. Critics argue that the ability of such malware to bypass antivirus detection indicates a need for improved security protocols and user education regarding safe download practices.

Verbatim Quotes

  • “We spotted the campaign at microsoft-update[.]support, a typosquatted domain dressed up to look like an official Microsoft support page. The site is written entirely in French (but these campaigns tend to spread quickly) and presents a fake cumulative update for Windows version 24H2, complete with a plausible KB article number. A large blue download button invites users to install the update.” — Malwarebytes
  • “The malware might even circumvent the antivirus you've installed on your Windows 11 PC.” — Malwarebytes

Conclusion

The emergence of this fake Windows 11 24H2 update campaign underscores the necessity for users to remain vigilant when downloading software updates. By adhering to official channels for updates and maintaining robust security practices, users can better protect themselves against such sophisticated cyber threats.