Unofficial Windows 11 installer infects PCs with malware

If you purchase an independently reviewed product or service through a link on our website, BGR may receive an affiliate commission.

An unofficial Windows 11 upgrade is making the rounds. Users looking to upgrade their PC from Windows 10 to Windows 11 will want to keep an eye out for this unofficial installer. When downloaded and activated, the installer infects the target PC with info-stealing malware.

Don’t Miss: Tuesday’s deals: $174 AirPods Pro, Quest protein bars, $10 spring-loaded tactical knife, more

Today’s Top Deals

This unofficial Windows 11 upgrade will steal your private info

Microsoft Defender on Windows 11

Microsoft Defender on Windows 11

BleepingComputer says the campaign is currently active, and it’s trying to “poison search results” to push users to download the infected file. The unofficial Windows 11 upgrade is downloaded via a site that is meant to mimic Microsoft’s official website. Eagle-eyed users should note that the URL is quite different from what you’d see if visiting Microsoft’s website, though.

When users press the download button, they are given an ISO file that harbors the malware inside of it. If the user opens the ISO file, then the malware is installed, giving bad actors access to their information. A group of threat researchers at CloudSEK analyzed the malware and shared the results in a report with BleepingComputer.

CloudSEK named the malware in the unofficial Windows 11 upgrade Inno Stealer. The researchers on the project say that it doesn’t seem to have any similar code to other info-stealers out there. Additionally, they’ve found no evidence of the malware being uploaded to the Virus Total Scanning Platform, either.

How the malware infects your computer

Windows 11 Main

Windows 11 Main

CloudSEK says the loader file hides in the “Windows 11 setup” executable found inside of the ISO. When launched, that creates a temporary file named is-PN131.tmp. It then creates another .TMP file allowing the loader to write 3,078KB of data to your PC. The loader then spawns a new process utilizing the Windows API. Altogether, the Inno Stealer creates four different files within your system.

The Inno Stealer included in the unofficial Windows 11 upgrade then targets browsers and…