Look out — this Windows 11 installer is really malware

Windows 11 laptops
(Image credit: Microsoft)

Installing Windows 11 isn't that easy for many existing computers, thanks to the software's stringent hardware requirements. That's led many Windows 10 users to search for workarounds that dodge such obstacles. 

But be careful, because one supposed Windows 11 installer is really the RedLine stealer, a well-known piece of information-stealing malware that will infect your web browser and swipe your passwords, credit-card numbers, login-session tokens and even cryptocurrency tokens. (RedLine is one of several reasons you should not let your browser save your passwords.)

The malware was being distributed from a website at windows-upgraded[.]com, HP malware analyst Patrick Schläpfer reported in an official HP blog post yesterday (Feb. 8). HP noticed the bogus website Jan. 27, the day after Microsoft announced that Windows 11 would be available as a free download for all eligible devices.

"This campaign highlights once again how attackers are quick to take advantage of important, relevant and interesting current events to create effective lures," wrote Schläpfer. "Prominent announcements and events are always interesting topics for threat actors, which can be exploited to spread malware."

  • A quality Windows VPN is the simplest way to protect yourself online

How the fake Windows 11 installer works

The site looked just like an official Microsoft site, right down to the OS maker's logo, site layout and minimalist design aesthetic. "Get Windows 11" was prominently displayed, and underneath that was a button that said "DOWNLOAD NOW."

If you clicked that button, Schläpfer said, you'd reach out to a Discord storage server and download a 1.5MB compressed file called Windows11InstallationAssistant.zip. Unpacked, the file expanded to a whopping 753 MB — a compression ratio of a phenomenal 99.8%, Schläpfer noted.

(Image credit: HP)

It turned out that a lot of the 751MB main file, Windows11InstallationAssistant.exe, was just padding consisting of repeated zeroes, hence the extreme compression ratio. Why would it need so much padding?

"One reason why the attackers might have inserted such a filler area, making the file very large," wrote Schläpfer, "is that files of this size might not be scanned by an antivirus and other scanning controls, thereby increasing the chances the file can execute unhindered and install the malware."

If you run Windows11InstallationAssistant.exe, you get a command-line operation that lasts exactly 21 seconds, then downloads what looks like a JPEG file called win11.jpg. 

Sounds harmless, right? Not quite — if you read the JPEG's code backwards, you get a dynamic-link library (DLL) file that contains the RedLine information stealer, a payload that lands in your lap when you run the purported "Installation Assistant" on your PC.

(Image credit: HP)

RedLine "collects various information about the current execution environment, such as the username, computer name, installed software and hardware information," Schläpfer explained. "The malware also steals stored passwords from web browsers, auto-complete data such as credit card information, as well as cryptocurrency files and wallets."

Even though the windows-upgraded[.]com site is no longer up, it will be easy for the crooks to try again at a different domain, or even to use a different lure. In fact, Schläpfer noted that the same baddies seem to have been behind a very similar campaign back in December that used a fake Discord installer site to distribute RedLine. 

How to protect yourself from this malware attack

To protect yourself from RedLine and other forms of malware, check the URL (web address) of every site from which you download software, and run each installer file through an antivirus scanner before you open it. (Most of the best Windows antivirus programs recognize RedLine for what it is.) 

And use common sense — a random website that doesn't have "microsoft.com" in the domain name but offers Windows installations anyway isn't likely to be legit.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Reddit logo and Reddit logo on phone
Hackers have created hundreds of fake Reddit sites to spread info-stealing malware
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
Man typing on Windows 11 laptop
Microsoft will let you install Windows 11 on unsupported PCs after all — what you need to know
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
Windows 11 logo on a laptop screen
I reviewed Windows 11, and these are the 5 new features I'm most excited about for 2025
Latest in Malware & Adware
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
A laptop displaying the Chrome logo
Don't click this — malicious ads impersonating Google Chrome spreading dangerous malware
and image of the Google Chrome logo on a laptop
Google Docs under attack from info-stealing malware — how to keep your data and your emails safe
MacBook Pro 2021 (16-inch) on a patio table
Millions of Mac owners urged to be on alert for info-stealing malware
Latest in News
3D printed models of alleged iPhone 17 Air and iPhone 17 Pro design
iPhone 17 Air dummy model shows off Apple’s big design change
MacBook Air M4
MacBook Air M4 just finally solved a decades-old problem — here's what's fixed
Cartoon image of three people using smartphones and laptops
NordVPN reinforces its security credentials with independent audit
Christopher Briney as Conrad and Lola Tung as Belly in The Summer I Turned Pretty
Prime Video top 10 shows — here’s the 3 worth watching right now
RTX 50 series GPUs
I was hyped for Nvidia's RTX 5060 Ti and RTX 5050 — until I saw these leaked specs
iPhone 17 Air render
iPhone 17 Air screen size and specs leak — here's what you need to know
  • USAFRet
    Why would one go anywhere besides Microsoft for an OS install?
    Be it Win 10, 11, or other?

    That is just asking begging for malware.
    Reply
  • Wolfshadw
    'Cuz Micro$oft is evil and if I can get the OS for free, hahaha!

    -Wolf sends
    :rolleyes:
    Reply