Scammers Impersonating Windows Defender to Push Malicious Windows Apps
ID: f38a0a91-ae10-5d53-99cf-89b140c16c1e
STIX ID: report--f38a0a91-ae10-5d53-99cf-89b140c16c1e
Feed Name: McAfee Labs Blog
Threat Score
**McAfee advisory:** Attackers use deceptive Windows-style push notifications to lure victims to updatedefender.online, which serves a signed MSIX installer that installs a data‑stealing trojan (Eversible.exe) that harvests system details, browser/profile data, and cryptocurrency wallet information; the report includes malware hashes, the malicious domain, detection status, and user mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
