Since Windows 11 was first released in June 2021, it has attracted many people to download and install it, and upgrade their computers to the latest operating system. Where there are topics, there will be people who want to use these high-profile points to invade your world. Since the beginning, there have been many fake and malicious Windows 11 installations to lure users who want to try it out. Although they disappeared for a while, they seem to be back again and more dangerous.

Fake official Windows 11 upgrade website makes a comeback, spreading fake RedLine Stealer malware files
The reason why there were so many fake upgrade files circulating on the Internet at first was that Windows 11 was not open to the public from the beginning, but was aimed at Insider test members with more technical foundation and knowledge. However, it is now open to everyone to upgrade, and plans to accelerate popularization are also in progress, making the current situation a bit delicate.

New malware campaign is caused by Discovered by HP Security Research Team, they found a new fake Microsoft official website on the Internet, but in fact it uses a very similar domain name “Windows-upgraded.com” and a web design that is so similar to the real Window 11 official website that it looks real. When people see it, it is easy to relax their guard and believe it. When you click the “Download Now” button twice, a compressed file named “Windows11InstallationAssistant.zip” (Windows 11 Installation Assistant) will be downloaded. After decompression, the original 1.5MB file immediately expands into a 753MB file, which contains six Windows DLLs, an XML file and a portable executable file. One reason for files to be very large is that antivirus and other scanning tools may not be able to scan files of this size, allowing malicious files to execute and install unimpeded.
▲Fake official Windows download website
After reverse analysis, HP found that this so-called Windows 11 installer contains the payload of the RedLine Stealer malicious stealer. As the name suggests, it can lurk in your computer and collect user names, computer names, installed software and hardware information. In addition, it can also steal sensitive personal data such as passwords, financial credentials, credit card automatic input data, and cryptocurrency wallets from your web browser, seriously damaging the financial and personal security of infected users.
▲RebLine steals the process execution method of the program
The newly discovered malware once again highlights how unscrupulous people can quickly use important, relevant and interesting current hot topics to build the most effective bait for users. For threat actors, these hot topics and events are the most effective for spreading malware. Since such activities usually rely on users to actively download software from websites as the initial source of infection, it is recommended that everyone be careful to choose trustworthy and reliable sources when downloading and installing software to avoid falling into various and ever-changing traps.
Source: KOCPC Chinese