Back Mezha.Ua Fake Windows 11 support site offers 'update' that steals data and evades antiviruses - Межа
Cybersecurity firm Malwarebytes is reporting a fake Windows support site that offers a "cumulative update" for Windows 11 24H2. The page and file are not suspicious at first glance. Clicking the "Download Update" button downloads an 83MB package that is capable of stealing "passwords, payment details, and account access."
The package was built using WiX Toolset 4.0.0.5512, which Malwarebytes describes as a "legitimate open source installer." The file is named WindowsUpdate 1.0.0.msi, Microsoft is listed as the author in the appropriate field, and the name field says Installation Database. The reports "logic and data required to install WindowsUpdate."
" At the time of analysis, VirusTotal showed zero detections across 69 engines for the main executable and 62 for the VBS launcher. No YARA rules matched, and behavioural scoring classified the activity as low risk.
This is not a failure of any single tool. It's the intended result of the malware's architecture .
Individually, each piece looks harmless. It's only when you follow the full chain — VBS launcher to Electron app to renamed Python process to data collection and exfiltration — that the activity becomes clearly malicious ," the company describes the difficulty of detecting malware.
The website address contains the string microsoft-update.support (the real technical support address is support.microsoft.com) . Malwarebytes has already added the threat to its malware detection service database.
Read also: Hackers hacked CPUID website and distributed malicious versions of HWMonitor and CPU-Z
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
