logo

Fake IT support sites push malicious PowerShell scripts as Windows fixes

ID: 451c7889-b0b7-54d3-ae0f-086ae7424527

STIX ID: report--451c7889-b0b7-54d3-ae0f-086ae7424527

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-30

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Fake IT support websites—promoted through hijacked YouTube videos exploiting users searching for a Windows Update 0x80070643 fix—lure victims into copying and executing PowerShell scripts or importing obfuscated Registry files that download and install the Vidar infostealer; once installed the malware harvests credentials, cookies, credit cards, crypto wallets, Authy databases, and other sensitive data and persists via autostart entries. eSentire and BleepingComputer documented the abusive domains and the delivery techniques and recommend obtaining fixes only from trusted sources or hiding the problematic KB if the WinRE partition cannot be resized.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.