HomeSecurityFake Windows 11 upgrade installs malware

Fake Windows 11 upgrade installs malware

A fake Windows 11 upgrade bundled with malware that steals browser data and cryptocurrency wallets is being used by hackers to lure unsuspecting users.

See also: New features coming soon to Windows 11

Fake upgrade

The campaign uses search results to promote a website that mimics Microsoft's promotional page for Windows 11, from which it offers information-stealing software.

Microsoft offers an upgrade tool so users can check for the company's latest operating systems (OS). However, the tool requires support for Trusted Platform Module (TPM) version 2.0, which is present on machines that are no older than four years.

Hackers are targeting users who immediately proceed to install Windows 11, without first checking whether the operating system meets certain specifications.

The malicious website offering the fake upgrade of Windows 11 remains active. It features the official Microsoft logos and an attractive button “Download now”.

If the visitor loads the malicious website via a direct connection (downloading is not available via TOR or VPN), they will receive an ISO file that supposedly protects the executable file from a new malware that steals information.

According to CloudSEK, the malicious actors behind this campaign are using a new malware that the researchers named “Inno Stealer” due to its use of the Windows installer, Inno Setup.

Researchers say that Inno Stealer has no code similarities to other information-stealing products currently circulating, and they have found no evidence that the malware is uploaded to the Virus Total.

The loader file is the “Windows 11 setup” executable file contained in the ISO, which when launched, drops a temporary file named is-PN131.tmp and creates another .TMP where the loader writes 3,078 KB of data.

See also: Microsoft: New Windows 11 security feature requires “clean install”
Windows 11

CloudSEK explains that the loader creates a new process using the CreateProcess Windows API, which helps create new processes, create persistence, and create four files.

Persistence is achieved by adding a .LNK file to the startup directory and using icacls.exe to set its access permissions for stealth.

Two of the four files installed are Windows command scripts to disable registry security, add Defender, uninstall security products, and delete the shadow volume.

According to the researchers, the malware also removes security solutions from Emsisoft and ESET, likely because these products detect it as malicious.

The third file is a command execution utility that runs with the highest system privileges, and the fourth is a VBA script required to run dfl.cmd.

In the second stage of infection, a file with the .SCR is dropped into the C:\Users\\AppData\Roaming\Windows11InstallationAssistant directory of the compromised system. This file is the agent that unpacks the info-stealer payload and executes it by spawning a new process called “Windows11InstallationAssistant.scr”.

Inno Stealer's capabilities are typical of this type of malware, including collecting web browser cookies and stored credentials, data in cryptocurrency wallets, and data from the file system

See also: Microsoft will block vulnerable drivers in Windows 10, Windows 11

The entire Windows 11 upgrade situation has created a fertile ground for the proliferation of these attacks and it is not the first time such a thing has been reported.

It is recommended that you avoid downloading ISO files from obscure sources and only perform major operating system upgrades from the Windows 10 or download the installation files directly from the source.

If an upgrade to Windows 11 is not available, there is no point in trying to bypass the restrictions manually, as this comes with a number of drawbacks and serious security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS