Beware Fake Windows 11 Updates: How to Tell the Real Thing From Malware
OWindows updates are supposed to make your computer safer.
That makes them an excellent disguise for malware.
Attackers know most people are used to seeing messages such as:
Update available
Restart required
or:
Install the latest Windows security update
So instead of asking you to install something obviously suspicious, they imitate a process you already trust.
Recent campaigns have used convincing fake Microsoft websites and advertisements to persuade Windows users to download supposed Windows 11 updates that were actually malware. One 2026 campaign analysed by Malwarebytes used a Microsoft-looking support site and a fake cumulative update installer designed to steal sensitive information. (malwarebytes.com)
The safest rule is simple:
Windows updates should normally come through Windows Update—not from a random website, advert, email or pop-up.
What Does a Fake Windows Update Look Like?
A fake update may appear as:
- a Microsoft-looking webpage
- an online advertisement
- an email
- a browser pop-up
- a fake support page
- a download pretending to be a cumulative update
Modern fake sites can be extremely convincing.
They may include:
- Microsoft logos
- Windows 11 branding
- realistic colours and fonts
- plausible KB numbers
- professional wording
- fake installer metadata
That is why judging a page purely by how professional it looks is no longer enough.
A Real Windows Update Usually Does Not Need You to Download an MSI From a Random Site
For an ordinary Windows 11 PC, start here:
Settings > Windows Update
That is the normal place to:
- check for updates
- install quality updates
- install feature updates
- see restart requirements
Microsoft continues to deliver supported Windows 11 cumulative updates through its Windows servicing infrastructure. (support.microsoft.com)
If a webpage suddenly says:
“Your PC urgently needs KBxxxxxxx — click here to download”
do not assume it is legitimate simply because the number looks convincing.
Open Windows Update yourself.
Never Trust the Branding Alone
A scammer can copy:
- logos
- icons
- page layouts
- screenshots
- wording
very easily.
The recent fake-update campaign went further by packaging its malware using legitimate developer technology and giving the installer properties that made it appear Microsoft-related. (malwarebytes.com)
That means:
Looks like Microsoft
is not proof.
Check:
- where you found the page
- domain name
- whether Windows itself offered the update
- whether the download is genuinely from Microsoft
Be Suspicious of Updates Delivered Through Ads
One particularly effective 2026 technique involved paid Facebook advertisements promoting what appeared to be Windows 11 downloads.
The ads led users to near-copy Microsoft download pages, but the installer was malicious and designed to steal information including browser credentials and cryptocurrency-wallet data. (malwarebytes.com)
The important lesson is:
An advert appearing on a major platform does not prove the download is trustworthy.
Advertising platforms can carry malicious campaigns just like ordinary websites can.
If you see an advert telling you to update Windows:
ignore the advert and open Windows Update yourself.
What Can Fake Update Malware Steal?
The 2026 campaign analysed by Malwarebytes behaved as an information stealer.
The malicious installer was designed to target information including:
- saved credentials
- browser data
- account sessions
- Discord credentials/tokens
- payment information
and installed persistence mechanisms so it could continue running after a restart. (malwarebytes.com)
That means the impact can extend well beyond the computer itself.
A compromised PC can lead to:
- Microsoft 365 account compromise
- email takeover
- stolen passwords
- financial fraud
- compromised social accounts
- further phishing attacks
For a business, one employee installing a fake update can become an organisation-wide security incident.
Why Antivirus May Not Catch It Immediately
Users sometimes assume:
“Defender didn't block it, so it must be safe.”
That is dangerous.
The malware campaign Malwarebytes analysed used legitimate development components, obfuscation and techniques intended to make the installer appear less suspicious. At the time it was analysed, some malicious components had very low detection rates. (malwarebytes.com)
Security software is important.
But it is not infallible.
You still need safe user behaviour.
Use Microsoft Defender SmartScreen
Windows and Microsoft Edge include reputation-based protections intended to identify malicious websites and downloads.
Microsoft says Defender SmartScreen can:
- evaluate websites
- identify known phishing or malicious sites
- warn about suspicious downloads
- help block tech-support scam pages. (support.microsoft.com)
Check:
Windows Security > App & browser control
and make sure reputation-based protections have not been disabled without a specific reason.
Again, SmartScreen is a safety layer.
It should not replace judgment.
Watch the Domain Name
Fake update sites frequently rely on domains that look vaguely official.
For example, the campaign analysed by Malwarebytes used:
microsoft-update[.]support
which is not an official Microsoft domain. (malwarebytes.com)
Attackers may use words such as:
- microsoft
- windows
- update
- security
- support
inside a domain to make it feel genuine.
Read the actual domain carefully.
Do not judge it by the page title or Microsoft logo.
Don't Click Urgent Update Links From Emails
A phishing email may say:
Critical Windows 11 update required
or:
Your computer is vulnerable — install immediately
Urgency is a classic phishing tactic.
Microsoft specifically warns that phishing attacks commonly create a sense of urgency to make users act before thinking. (support.microsoft.com)
If an email tells you Windows needs updating:
- Do not click the link.
- Open Settings yourself.
- Open Windows Update.
- Check there.
If the update is genuine and applicable, Windows can normally tell you.
Browser Pop-Ups Are Not Windows Update
A website may suddenly display a full-screen message claiming:
Windows security update required
or:
Your computer is at risk
A browser page cannot be trusted simply because it looks like a Windows dialog.
Microsoft warns that malicious websites can:
- go full screen
- imitate Windows errors
- play alarming messages
- make the browser appear locked. (support.microsoft.com)
If a webpage is demanding that you install software:
close it.
If necessary:
Alt + F4
or use Task Manager to close the browser.
Real Microsoft Error Messages Do Not Tell You to Call a Phone Number
This is more commonly associated with support scams, but it remains a useful rule.
Microsoft states explicitly:
genuine Microsoft error and warning messages do not include a phone number for you to call. (support.microsoft.com)
So if an “update” page says:
Call Microsoft Support immediately on 0800…
it is not a genuine Windows system warning.
What About the Microsoft Update Catalog?
There are legitimate scenarios where administrators manually download Windows update packages.
Microsoft provides the Microsoft Update Catalog for this purpose.
That is different from downloading an unknown MSI from a website claiming to host a Windows update.
For normal users, Windows Update remains the safest route.
For IT professionals manually deploying a specific KB, use official Microsoft infrastructure and verify exactly what you are downloading.
What If Windows Says Your PC Is Up to Date?
Do not assume a website knows better.
Microsoft may deliberately hold back a feature update because of a known compatibility issue.
These safeguard holds are intended to prevent devices from installing an update likely to cause problems. Your existing Hamilton Group guidance explains this correctly. (hgmssp.com)
So if:
Windows Update says you're current
but:
a website says you urgently need a newer version
trust the managed Windows update path until you have verified otherwise.
Do not force an update from an unfamiliar download.
Business PCs Should Ideally Be Centrally Managed
For organisations, relying on each employee to decide whether an update prompt is genuine is unnecessary risk.
Windows updates can be managed centrally using technologies such as:
- Microsoft Intune
- Windows Autopatch
- Windows Update policies
That allows IT to determine:
- which updates are deployed
- when they install
- when restarts happen
- whether a device is compliant
It also creates a simple employee rule:
If a website asks you to update Windows manually, don't do it. IT manages updates.
That is far easier to communicate.
What Should Staff Be Told?
Keep the rule simple.
I'd give employees something like:
Windows updates come through Windows Update or our IT management system. Do not install a Windows update offered through an advert, browser page, email or unexpected download. If you are unsure, contact IT.
That is much more useful than asking employees to inspect:
- digital signatures
- installer hashes
- certificate chains
Most users should not need to become malware analysts.
Give them a clear safe path.
What If You Downloaded the Fake Update but Didn't Open It?
Do not run it.
Delete the downloaded file.
Then:
- Empty Downloads where appropriate.
- Run a Microsoft Defender scan.
- Check whether the browser downloaded anything else.
- Inform IT if it is a company device.
If the file never executed, the risk is substantially lower.
But on a business device, reporting it still helps security teams check whether other employees encountered the same campaign.
What If You Ran the Fake Update?
Treat this much more seriously.
If you executed an unexpected Windows-update installer:
disconnect the machine from the network if compromise is suspected.
Then contact IT/security.
Do not continue using it for:
- banking
- Microsoft 365
- password-manager access
- administrative work
until it has been investigated.
Microsoft recommends running a full Windows Security scan after suspected scam/malware exposure. (support.microsoft.com)
For a business system, I would go further and treat it as a potential endpoint compromise.
Change Passwords From a Clean Device
This is critical if the malware could be an information stealer.
Do not immediately change all your passwords on the potentially infected computer.
If malware is stealing:
- keystrokes
- browser sessions
- authentication data
you could simply hand over the new credentials too.
Use a known-clean device.
Prioritise:
- email/Microsoft 365
- password manager
- banking
- social accounts
- administrator accounts
Also revoke active sessions where appropriate.
MFA Helps — but Infostealers Can Steal Sessions Too
Multi-factor authentication is still extremely important.
But do not assume:
“I have MFA, therefore stolen browser data doesn't matter.”
Modern information stealers may target:
- cookies
- session tokens
- browser data
which can sometimes allow attackers to abuse an already authenticated session.
That is why incident response may need to include:
password change + session revocation + MFA review
rather than password change alone.
Check Persistence
The 2026 fake Windows update campaign used persistence so the malware could launch again after reboot, including a Run registry entry designed to look like Windows Security and a startup shortcut. (malwarebytes.com)
That is another reason:
“I restarted and everything looks fine”
does not prove the malware is gone.
A security investigation should look beyond whether the original installer is still visible.
Businesses Should Consider Rebuilding the Device
Where a credential-stealing malware infection is confirmed, simply deleting one detected file may not provide enough confidence.
Depending on:
- malware behaviour
- privileges obtained
- business sensitivity
- endpoint-security evidence
the safest approach may be to:
wipe/rebuild the endpoint from a known-good state
and restore business data carefully.
The objective is not merely:
Defender says no threats found now.
It is:
Can we trust this endpoint again?
The Fake Update Checklist
If an unexpected Windows update appears:
Ask where it came from
Windows Settings / managed IT platform?
Probably legitimate path.
Advert / browser page / email?
Treat with suspicion.
Check whether Windows Update offers it
Open:
Settings > Windows Update
yourself.
Check the domain
A page containing the word Microsoft is not necessarily Microsoft.
Never install a random MSI because it claims to be a KB update
Verify through official channels.
Keep SmartScreen and Defender enabled
They add important protection.
If you ran it
Stop using the machine for sensitive work and contact IT/security.
How Hamilton Group Can Help
Fake-update campaigns are particularly dangerous because they exploit something employees have been trained to do:
install security updates promptly.
Hamilton Group can help businesses reduce that risk through:
- managed Windows updates
- Microsoft Intune
- Windows Autopatch
- Microsoft Defender
- endpoint protection
- phishing/security awareness
- malware investigation
- Microsoft 365 account security
- incident response
For managed business devices, employees should not have to decide whether a random internet download is the latest Windows security patch.
Updates can be controlled centrally and suspicious prompts can be checked by IT.
Visit hgmssp.com or call 0330 043 0069 if you are concerned that a Windows device may have downloaded or executed a fake update.