written by
Joey Hoelscher

Seriously? A Fake Windows 11 Update

Fake Windows Update Disguising Malware Fraudulent Updates 3 min read
Fake Update...Beware!

​Credit where it’s due: we have to admit, scammers are a persistent bunch.

It feels like every three weeks or so we hear about a new approach to hack, scam, or otherwise access devices and data.

This one’s a doozy… both because of how simple it is, and how easy it is to fall victim to it.

Scammers Have Created a Fake Windows 11 Update

It sounds almost impossible, but scammers have managed to create something that looks almost exactly like a real Windows 11 update.

You can probably guess where this is going: click the link, download the update, and boom — it wasn’t actually an update. It was malware, and now you’re infected.

It works because people inherently tend to trust big tech, at least in some ways. When Microsoft says “hey it’s time to update Windows to make it more secure,” very few consumers or businesses think “yeah, that might just be a scam.”

That’s exactly what the scammers are counting on.

If they can get you to that very realistic-looking webpage that seems like a legitimate Microsoft page, they know your guard will already be down.

The Fake Update Looks Surprisingly Good

It used to be true that most phishing websites were rough. Thrown together, bad design, tons of typos. That’s changing in the age of AI: writing moderately convincing, polished copy only takes a few clicks.

The same thing is happening to malware itself. This fake update relies on a very convincing website for its first line of attack, but the code itself is cleaner, built with legitimate tools and stuffed full of labels and properties that make it look real.

In other words: even if someone on your team gets tricked into downloading malware, decent security software will spot that malware, identify it for what it is, and save the day. But this malware is “clean” enough (or clean-looking enough) that it’s tricking some security software, taking away that line of defense.

Best Practices for Avoiding This Attack

In this situation, the attack is pretty devious. But the responses businesses should make are actually pretty straightforward.

Let’s walk through a few.

1. Install Updates Only from Settings

First up: no one should be installing updates from emails, pop-ups, or any other internet locations.

This is key: in virtually every instance, Windows Updates install from the Settings app in Windows itself. The scammers can’t get into that space, at least not unless your system is already deeply, deeply compromised.

So remember for yourself and teach your team: never go for a Windows Update anywhere other than in Settings itself.

2. Edge Case: Manually Find It

That said, there are certain edge cases — you’ll probably never encounter one — where individuals do need to manually initiate an update.

If that ever happens at your business, here’s the right move: manually open Microsoft’s website and find the update there. Yes, this is annoying, and it won’t necessarily be easy. But the good news is that if you’re one of those edge-case people, you probably know your way around Microsoft’s website already.

3. Best Move: Endpoint Management (and Managed Services)

The best move of all is setting up your business IT so that team members never have to worry about Windows updates at all.

Endpoint management is the practice of keeping PCs running and up to date centrally and remotely. When you set up your business PCs this way, IT pushes updates only after they vet them. Individual users can’t install them on their own, which gives you another layer of protection.

If you don’t have sufficient IT capacity for something like this, that’s where we come in. Blue Ridge Technology is a managed IT services group in greater Asheville, NC. We help businesses set up their tech infrastructure the right way, including with managed endpoint protection.

We’re here to help: Give us a call today or schedule a 30-minute conversation.

Fake Windows Updates malware Fraudulent Updates