Devious Malware Hosted on Discord Pretends to be Windows 11 Installer
A malware hosted on Discord pretends to be a Windows 11 installer.
An installer has been spotted trying to expose personal information to hackers.
Don’t download an installer.
Many actors have already installed malware while attempting to install the latest OS on their PCs.
They found that windows-upgraded.com is attempting to distribute RedLine Stealer.
The website looks like a mirror image of Microsoft’s own Windows 11 installer website.
The button “Download Now” leads to a dodgy installer.
It is called Windows11InstallationAssistant.zip, it contains six Windows DLLs, an XML file and it’s 1.5MB big compressed.
The file has a compression ratio of 99.8%.
They said to achieve this ratio, it likely contains padding.
It looks like a bunch of 0x30 byte codes and has no impact on the operation of the file.
They also noted that this kind of attack was also analyzed in 2021.