top of page
Search

Beware This Fake Windows 11 Update


You probably don’t think twice when you see a Windows update.


You click a button, wait a few minutes, restart your computer at the worst possible time, and get back to work.


Updates are supposed to protect your computer. That sense of trust is exactly what cybercriminals are trying to use against you.


Security researchers recently found a fake Windows 11 update on a website designed to look like an official Microsoft support page. It offered what appeared to be a normal Windows 11 update.


But the download did not fix Windows.


It installed malware designed to steal passwords, payment information, browser data, and access to online accounts.


The Fake Website Looks Convincing


Older scam websites were often easy to spot. They had strange wording, terrible graphics, and enough spelling mistakes to make your third-grade teacher cry.


This scam is much more polished.


The fake website copies the look and language of Microsoft’s support pages. It offers a believable Windows 11 update with a large download button. The original campaign was aimed at French-speaking users, but the same idea can easily be reused in other countries and languages.


Even the website address was designed to look believable. But it did not end in microsoft.com, which is an important warning sign.


Once downloaded, the installer also appeared legitimate. Its file properties listed Microsoft as the author, and it was built using a real software development tool.


The crooks did their homework. Unfortunately, it was the kind of homework that steals your passwords.


Security Software May Not Catch It Immediately


The malware hides inside several legitimate software components. When researchers first examined the main program, dozens of antivirus scanning engines failed to identify it as malicious.


That does not mean antivirus software is useless. It means no single security product can stop every new threat the moment it appears.


Modern security requires layers, including:

  • Managed endpoint protection

  • Threat monitoring

  • Email and web filtering

  • Limited user permissions

  • Employee security training

  • Reliable backups

  • A clear process for reporting suspicious activity


Security tools matter, but employees still need to pause when something unexpected asks them to install software.


What Happens If Someone Installs It?


Once running, the malware can attempt to collect passwords, payment details, browser information, login sessions, and other sensitive data.


It also creates ways to restart after the computer is rebooted. Some of its files use names connected to Windows Security and Spotify so they are less likely to draw attention.


This can lead to more than one infected computer. Stolen credentials may give criminals access to email, cloud services, financial accounts, or other business systems.


That harmless-looking update can become a company-wide problem surprisingly fast.


How to Avoid a Fake Windows 11 Update


The safest rule is simple: Keep Windows updates inside Windows.


On a Windows 11 computer:

  1. Open the Start menu.

  2. Select Settings.

  3. Click Windows Update.

  4. Select Check for updates.


For most users, this is the only place Windows updates should be installed.


Microsoft also provides standalone updates through the official Microsoft Update Catalog. However, employees should not download updates manually unless their IT provider has instructed them to do so.


If an email, website, advertisement, or pop-up claims you need an urgent update, do not use the link it provides. Open Windows Settings and check for updates directly.


Urgency is one of the oldest tricks in the scammer handbook. “Install this right now” is often followed by “Congratulations, your afternoon is ruined.”


Teach Employees to Pause


You do not want employees to become afraid of every update message. You want them to recognize when something does not follow the normal process.


A useful company rule is:

If an unexpected website, email, or pop-up asks you to install an update, stop and contact IT.

Employees should also know how to report something they have already clicked. Punishing people for honest mistakes can cause them to hide problems, giving malware more time to spread.


Fast reporting is much more valuable than pretending nobody ever clicks the wrong button.


What If You Already Installed It?


If you think you installed an update from an unfamiliar website, disconnect the computer from the network and contact your IT provider immediately.


Do not continue using the computer to log in to email, banking sites, or business systems. The malware may be collecting those credentials.


Your IT provider may need to:

  • Isolate and inspect the computer

  • Remove the malicious software or rebuild the device

  • Reset passwords from a clean computer

  • Sign users out of active sessions

  • Review email and cloud accounts for suspicious access

  • Confirm that other computers were not affected


Changing a password may not be enough if a criminal has already stolen an active login session. That is why the incident should be investigated instead of simply deleting a suspicious file and hoping for the best.


Routine Actions Still Need Security


Cybercriminals know people are cautious around strange attachments and obvious phishing emails. That is why they are copying trusted, routine activities instead.


A Windows update feels normal. People expect to see one, and they usually want to get it over with quickly.


That makes it a nearly perfect disguise.


Keep updates inside Windows, question unexpected download requests, and make sure employees know they can contact IT before clicking.


If you would like help managing updates, monitoring threats, or training your employees, click here. We can help protect your business without making every Windows notification feel like a hostage situation.


Technical details about this campaign were reported by Malwarebytes.

 
 
 
bottom of page