Site icon WinCert

Fake Microsoft Site is distributing bogus Windows 11 downloads

<p>Security experts are warning Windows users to be extremely cautious when downloading Windows 11 installation images&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4294" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2021&sol;07&sol;windows-11-6379123&lowbar;640&period;png" alt&equals;"" width&equals;"640" height&equals;"524" &sol;><&sol;p>&NewLine;<p>It appears that a fake site has appeared that looks very similar to the original Microsoft website and is distributing bogus Windows 11 installation images which contain malware&period; Usually&comma; these scams target users that are trying to avoid paying for the software or the ones who are trying to get early access to the latest versions&period; Fake sites usually look almost identical to the original Microsoft site except for the URL address&period;<&sol;p>&NewLine;<p>The problems start with the Download Now button which redirects the users to a zip archive called &&num;8220&semi;Windows11InstallationAssistant&period;zip&&num;8221&semi; that contains bogus Windows 11 installation&period; Scammers have also made ZIP files for users with slow internet connections that are 1&period;5MB in size and contain only one executable file named Windows11InstallationAssistant&period;exe&period;<&sol;p>&NewLine;<p>Running Windows11InstallationAssistant&period;exe will not start Windows 11 installation but instead will download a JPG image and run a code that will replace itself with the RedLine Stealer code&period; This is the same malware used to <a href&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;cast&sol;kraken-botnet-could-sweep-your-crypto-wallets&sol;" target&equals;"&lowbar;blank" rel&equals;"noopener">sweep users&&num;8217&semi; crypto wallets<&sol;a>&period; RedLine Stealer malware is one of the most popular info stealers out there&period; It is capable of stealing entire identity info from browsers including saved passwords&comma; credit card information&comma; autocomplete forms&comma; etc&period; It can also grab inventory data including username&comma; location&comma; hardware&comma; and software details&period;<&sol;p>&NewLine;<p>To be on the safe side&comma; be very careful and always double-check the sources of Windows 11 installation files&period;<&sol;p>&NewLine;

Exit mobile version