Fake Windows Support Website Delivers Malware Disguised as Update
A fraudulent website posing as a legitimate Windows support page is tricking users into downloading malware disguised as a 'cumulative update' for 'Windows Update version 24H2'. The fake update, which appears convincing at first glance, is actually a malware package capable of stealing passwords, payment details, and account access information. The malware is cleverly disguised using the WiX Toolset, a legitimate open-source installer framework, and is designed to evade detection by antivirus software. The malicious package is named 'WindowsUpdate 1.0.0.msi' and falsely claims to be from Microsoft. The domain used by the scammers, 'microsoft-update[.]support', is a key indicator of the scam, as the genuine Microsoft support site is 'support.microsoft.com'.