logo

This fake Windows support website delivers password-stealing malware

ID: 38bfe23f-810d-5952-ac90-25342bc8427b

STIX ID: report--38bfe23f-810d-5952-ac90-25342bc8427b

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-28

...
...

**Fake Microsoft update (microsoft-update.support) distributes a multi-stage infostealer via an MSI that installs an Electron app and a runtime-deployed Python payload to steal credentials, payment data, and tokens; it evades detection by using legitimate binaries, heavy script obfuscation, renamed processes, runtime package installs, and exfiltrates via services like gofile and C2 domains, persisting via Registry Run key and a Startup shortcut.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.