logo

Scammers Impersonating Windows Defender to Push Malicious Windows Apps

ID: f38a0a91-ae10-5d53-99cf-89b140c16c1e

STIX ID: report--f38a0a91-ae10-5d53-99cf-89b140c16c1e

Feed Name: McAfee Labs Blog

Threat Score
65/100

Date Published: 2021-05-17

Date Updated: 2026-04-28

Author: Craig Schmugar

...
...

**McAfee advisory:** Attackers use deceptive Windows-style push notifications to lure victims to updatedefender.online, which serves a signed MSIX installer that installs a data‑stealing trojan (Eversible.exe) that harvests system details, browser/profile data, and cryptocurrency wallet information; the report includes malware hashes, the malicious domain, detection status, and user mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.