Fake IT support sites push malicious PowerShell scripts as Windows fixes
ID: 451c7889-b0b7-54d3-ae0f-086ae7424527
STIX ID: report--451c7889-b0b7-54d3-ae0f-086ae7424527
Feed Name: Bleeping Computer
Fake IT support websites—promoted through hijacked YouTube videos exploiting users searching for a Windows Update 0x80070643 fix—lure victims into copying and executing PowerShell scripts or importing obfuscated Registry files that download and install the Vidar infostealer; once installed the malware harvests credentials, cookies, credit cards, crypto wallets, Authy databases, and other sensitive data and persists via autostart entries. eSentire and BleepingComputer documented the abusive domains and the delivery techniques and recommend obtaining fixes only from trusted sources or hiding the problematic KB if the WinRE partition cannot be resized.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
