Your antivirus didn’t catch this fake Windows update

Fake Update

You update Windows because it asks you to. Click, wait, done. It’s one of the few IT habits nobody has to be trained on, because it feels safe by default.

In April 2026, that habit is exactly what a new attack is counting on.

A fake Windows 11 update started circulating that looks close enough to the real thing to fool most people, and close enough to fool most antivirus software too. According to security firm Malwarebytes, the fake update was hosted on a typosquatted domain, microsoft-update[.]support, styled to look like an official Microsoft page. It offered a cumulative update for Windows 11 24H2, complete with a believable KB article number and a big blue download button. Click it, and you’re not installing an update. You’re installing malware built to steal passwords.

It’s not a sloppy fake

Older scams like this were easy to spot. Bad grammar, a slightly wrong logo, a URL that didn’t quite match. This one isn’t that.

The malicious file was built using WiX Toolset, a legitimate open source tool that real developers use to package real Windows software every day. The installer is even labeled to match. Its author field reads Microsoft. Its title reads Installation Database. At a glance, and even at a fairly close glance, it looks like the genuine article.

Here’s the part that should get your attention. When Malwarebytes ran the file through VirusTotal, a service that checks a file against dozens of antivirus engines at once, it came back with zero detections across 69 of them. Not one flagged it as a threat. The reason is that the malicious code sits hidden inside an Electron shell, a common framework used to build legitimate desktop apps. Antivirus tools check the outer shell, see a familiar and legitimate framework, and wave it through. They never look at what’s packed inside.

Think of it like a guard checking IDs at the door. This one showed up with a real ID borrowed from a framework everyone recognizes, carrying something dangerous in a bag nobody thought to open.

Why this matters more for a business than a home user

A password stolen from your personal laptop is bad. A password stolen from someone on your team is worse, because that password is rarely just theirs. It might open your email, your accounting software, a client portal, or a shared drive with everyone else’s files on it.

Credential theft is usually not the end of an attack. It’s the beginning of one. Once an attacker has a working password, they can log into whatever that password protects, often without tripping any alarm, because as far as your systems are concerned, that’s just an employee logging in. From there it becomes a business email compromise, a fraudulent wire request, or a foothold into other accounts that reuse the same password.

This particular fake update is effective precisely because it targets the moment your team is least suspicious. Nobody double checks a Windows update. That’s the whole point of it looking routine.

What to do about it

Keep updates inside Windows. If you’re running Windows 11, the safest way to check for and install updates is through the built in Settings app, not a page someone linked in an email or a search result. If you genuinely need to grab something manually, go directly to support.microsoft.com and nowhere else.

It’s also worth tightening who can install software on company machines in the first place. If an employee doesn’t have local admin rights, a fake installer like this one has nowhere to run even if someone clicks it. That’s a bigger lever than any single antivirus update.

Treat multi-factor authentication, or MFA, as the backstop, not the extra step. This attack exists specifically to harvest a password. If a stolen password alone isn’t enough to get into an account, the whole scheme is a lot less useful to whoever is running it.

Antivirus caught none of this. That’s not an argument against antivirus, it’s an argument for layering something behind it: fewer people with the keys to install software, and a second factor standing behind every password. Click, wait, done still works fine, as long as the click happens inside Windows Update and not on a page some stranger sent you a link to. If you want help reviewing where your team stands on admin rights or MFA, we’re happy to take a look.

Microsoft is fixing Windows 11. Here’s the part that matters for your business.

You’ve probably made your peace with Windows 11 by now. It works. Your team knows it. Every so often something gets in the way: a restart prompt at the worst possible moment, an AI button you didn’t ask for, a File Explorer window that takes a beat too long to open. None of it is bad enough to rip out and replace. It’s just friction.

So when Microsoft announces it’s going to “fix the biggest issues” in Windows 11, the natural reaction is to file it under marketing and move on.

This time it’s worth a second look. In March 2026, Pavan Davuluri, who runs Windows at Microsoft, published a blog post laying out specific changes coming to the operating system over the following months. It reads less like a feature pitch and more like a list of complaints Microsoft finally decided to take seriously.

What’s changing

The headline item is less AI. Over the past year Microsoft pushed Copilot into more and more corners of Windows, including apps like Photos and Notepad where most people never wanted it. Davuluri says they’re cutting back on what he calls “unnecessary Copilot entry points.” Desktop widgets, the panels that throw news and weather at you, are being made quieter with better controls over what shows up.

Updates are getting attention too. Microsoft says they’ll be less disruptive, with more room to skip or pause them. File Explorer, the tool your whole team uses to find and move files, is supposed to get faster and more dependable. And taskbar repositioning is coming back, so you can move the taskbar to the side or top of the screen without a third-party tool. That was a Windows 10 feature that got cut, and Davuluri says it’s been one of the top requests he hears.

Individually, none of this is dramatic. The question is what it adds up to for a company running thirty of these machines instead of one.

The change that touches your business

Forget the taskbar for a minute. The change that matters most for a business is the one about updates.

Here’s why. A forced restart on your home PC is an annoyance. A forced restart across an office is lost work. It’s the employee who steps away for coffee and comes back to a rebooting machine and an unsaved file. It’s the update that lands in the middle of a billing run. It’s the morning where half your team is staring at a progress bar instead of working. Multiply a few of those by a payroll, and the cost of “minor inconvenience” stops being minor.

More control over update timing means you can keep machines current on security patches, which you have to do, without those patches landing in the middle of the workday. That’s not a personal-convenience feature. That’s an IT management feature wearing a consumer label.

The AI cleanup matters for a quieter reason. In a business, consistency is worth more than novelty. When Windows keeps shifting buttons around and surfacing features nobody asked for, every change is a small tax on the people who just want to do their jobs the way they did them yesterday. Fewer surprises on the screen means fewer “where did this go” questions and less time lost to the interface getting in the way.

What to do about it

Not much, yet. That’s the honest answer.

These changes are rolling out through the Windows Insider program first, which is the preview track where Microsoft tests things before they reach everyone. Putting your business machines on a preview build to get features early is a bad trade. You’d be volunteering your team as test subjects for software that isn’t finished. Let these land in the normal, stable updates. They’ll get to you.

What you can do now is treat update timing as a decision rather than something that happens to you. If forced restarts and badly timed updates are a recurring problem on your network, that’s manageable. The controls to schedule updates, defer them, and roll them out in a sensible order on a business network already exist, and they’re about to get better. Most companies just never set them up.

That’s the real takeaway here. Microsoft is making Windows 11 less annoying, and that’s good. If you want to optimize your workflow around the change rather than just wait for it, that is worth a read. But the difference between an operating system that gets in your team’s way and one that stays out of it was never only about Microsoft. It’s about whether someone is managing these machines on purpose. If nobody is, the new settings will sit there unused, same as the old ones.

If you’re not sure whether your team’s machines are set up to update on your schedule instead of Microsoft’s, we can take a look and tell you where you stand. It’s a small thing to check and a frustrating one to keep ignoring.