This fake Windows support website delivers password-stealing malware
ID: 38bfe23f-810d-5952-ac90-25342bc8427b
STIX ID: report--38bfe23f-810d-5952-ac90-25342bc8427b
Feed Name: Malwarebytes Blog
Threat Score
**Fake Microsoft update (microsoft-update.support) distributes a multi-stage infostealer via an MSI that installs an Electron app and a runtime-deployed Python payload to steal credentials, payment data, and tokens; it evades detection by using legitimate binaries, heavy script obfuscation, renamed processes, runtime package installs, and exfiltrates via services like gofile and C2 domains, persisting via Registry Run key and a Startup shortcut.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
