Fake Windows 11 Upgrade Infect Users With Info-stealing Malware

Hackers are using SEO poisoning to push a fake Windows 11 upgrade site that infects victims with information stealing malware.

Many users are unaware of the requirements for installing the latest Microsoft operating system. One of the requirements is support for Trusted Platform Module (TPM) version 2.0. This requirement is only available on machines that are not older than four years.

Exploiting users’ ignorance, attackers have now launched a malicious website that features the fake Windows 11 with Microsoft’s official logos and an inviting”Download Now” button.

According to researchers, this campaign uses a new malware named “Inno Stealer.” The malware was named Inno Stealer due to its use of the Inno Setup Windows installer.

The malware drops a file with the .SCR extension in the directory of the compromised system. The file unpacks the info-stealer payload and executes it by triggering a new process called “Windows11InstallationAssistant.scr.”

The malware collects web browser cookies and stores credentials, data in cryptocurrency, wallets and data from the file system. Targeted browsers are Chrome, Edge, Brave, Opera, Vivaldi, 360 Browser and Comodo.

Users are advised to avoid downloading ISO files from obscure sources and to perform important OS upgrades only within their Windows 10 control panel. They can also obtain the installation files directly from the source.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.