Fake Windows Support website offers 'cumulative update' for version 24H2 but delivers password-stealing malware that can avoid anti-virus detection

A computer screen with program code warning of a detected malware script program. 3d illustration
(Image credit: solarseven, via Getty Images)

Even though I've been immersed in all things tech for some time now, I'm not arrogant enough to think I'll never be caught out by a phishing email or downloading dodgy software. That's especially true as online scams grow in sophistication—for instance, there's a fake Windows support page that tricks users into downloading password-stealing malware.

The fake support page alleges a 'cumulative update' for 'Windows Update version 24H2,' complete with a KB article number that's passable at a glance. Anyone who actually hits the big blue 'Download the update' button will get a convincingly spoofed Windows Installer package. Unfortunately, this download is actually malware that can hoover up "passwords, payment details, and account access", according to cybersecurity company Malwarebytes.

So, that's how it escapes user notice—but it may also squeak past whatever anti-virus you have installed too. "At the time of analysis, VirusTotal showed zero detections across 69 engines for the main executable and 62 for the VBS launcher. No YARA rules matched, and behavioural scoring classified the activity as low risk," Malwarebytes reported. "This is not a failure of any single tool. It’s the intended result of the malware’s architecture."

Cracking this bad boy open, it becomes clear the package is flying under the radar due to an Electron shell obfuscating malicious JavaScript inside. In other words, your PC's automatic defences will ding the outer Electron layer—which is a free and open-source software framework used by plenty of legitimate apps—and won't wade far enough in to uncover the suss script at its core. I would admire such sneaky construction, were it not for all of the credential sniffing.

A screen shot of a Windows 11 user's desktop. The wallpaper is a photograph of a bear clinging to a tree stump. Over the top of this is the Windows Update pane accessed from the Settings menu.

(Image credit: Microsoft)

It's striking the lengths the scammers have gone to ensure this malicious page passes muster, but there is a key giveaway should you find yourself on this fake Windows website. Specifically, you should keep your eyes peeled for the dodgy domain 'microsoft-update[.]support'—Microsoft's genuine support hub is found at 'support.microsoft.com'.

Microsoft company also offers its own guide on how to download and install Windows updates legitimately for anyone at all unclear. Bottom line, the guide points users towards 'Windows Update' under 'Settings' in your operating system's Start menu, rather than an external webpage like the one in the scam. Malwarebytes has additionally updated its anti-virus offering to better detect the latest suss software, and now offers a full rundown of what to do next if you suspect you've downloaded it by mistake. After all, it can happen to anyone.

Secretlab Titan Evo gaming chair in Royal colouring, on a white background
Best PC gaming kit 2026

1. Best gaming chair: Secretlab Titan Evo

2. Best gaming desk: Secretlab Magnus Pro XL

3. Best gaming headset: Razer BlackShark V3

4. Best gaming keyboard: Asus ROG Strix Scope II 96 Wireless

5. Best gaming mouse: Razer DeathAdder V4 Pro

6. Best PC controller: GameSir G7 Pro

7. Best steering wheel: Logitech G Pro Racing Wheel

8. Best microphone: Shure MV6 USB Gaming Microphone

9. Best webcam: Elgato Facecam MK.2


👉Check out our list of guides👈

TOPICS
Jess Kinghorn
Hardware Writer

Jess has been writing about games for over ten years, spending a significant chunk of that time working on print publications PLAY and Official PlayStation Magazine. When she’s not investigating all things hardware here, she's either constructing a passionate defence of a 7/10 game, daydreaming about her debut novel, or feeling wistful about the last time she chased some nerds around a field with an oversized foam sword. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.