Fake software installers: disabling Windows Update and weakening Defender before intrusion

In this saga : Ingénierie sociale via terminal — ClickFix et variantes 2026· Episode 3/3

Cybersecurity Sep 3, 2026Add to bookmarks

Fake software installers: disabling Windows Update and weakening Defender before intrusion
Illustration : Momiji Shirogane

The Hacker News documents a campaign of fake software installers that begin by disabling Windows Update and reducing Microsoft Defender protections. This is no longer a classic drive-by attack: it's a preamble to a lasting intrusion.

The Facts

The Hacker News reported on September 2, 2026, an active campaign involving fake software installers—a classic drive-by download vector, but with a notable twist. Once executed, the fake installer doesn’t just drop a payload: it disables Windows Update and weakens Microsoft Defender protections before taking any further action.

The documented pattern:

  1. The user downloads an installer (via SEO, ads, or a fake official site).
  2. The installer requests admin privileges—nominally to “install the software.”
  3. Once granted, it modifies Windows Update settings (prolonged pause, component deactivation) and reduces Defender capabilities (folder exclusions, real-time function deactivation, service tampering).
  4. Only then is the main payload deployed—malware, RAT, or a foothold for future intrusion.

Who Is Affected

  • Windows home users and small businesses who download software via search engines or ads (bypassing the Microsoft Store or verified catalogs).
  • Workstations without centralized management—no MDM/AV enterprise controls, user has admin rights.
  • Personal devices used for remote work that connect to corporate networks (unmanaged BYOD).

Why This Matters

This evolution fits the trend of “social engineering via terminal” that we’ve been tracking—campaigns that exploit the trust of technically savvy users (fake CAPTCHAs, fake browser checks, ClickFix, TerminalFix). Here, the vector is more mainstream than ClickFix, but the logic is the same: turn a voluntary user action into a lasting compromise.

Three key points:

  1. Disabling Windows Update is strategic. Without updates, the machine remains vulnerable to known CVEs—the attacker keeps the doors open for future access, even after superficial cleanup of the initial payload.
  2. Weakening Defender preserves stealth. Instead of killing the antivirus (which would trigger alerts), the campaign blinds it—folder exclusions, component deactivation. The green light stays on.
  3. The chain is modular. The fake installer doesn’t carry the final payload; it prepares the ground. This lets operators deliver different payloads depending on the target (crypto-miner for individuals, ransomware for businesses, backdoor for high-value targets).

What to Do Now

  • Never download software from a search ad or result. Always use the official URL or a verified catalog (Microsoft Store, package manager like winget, official repo).
  • Regularly check Windows Update (Settings → Windows Update) and Defender (Windows Security → Virus & threat protection). A machine “paused” or with unexplained exclusions is a red flag.
  • In enterprise: enforce EDR + disable local admin rights—this is the only reliable barrier against such campaigns.
  • Post-incident: on a suspect machine, don’t just clean the visible malware—manually re-enable Windows Update and Defender, remove all unknown exclusions, then re-scan.
The Reverse Sequence

The fake installer disables Windows Update and weakens Defender AV *before* dropping the main payload. The compromise isn’t a single event—it’s an environment primed to accept *any* payload, now or later.

Key Takeaway: When an “installer” asks for admin rights and takes more than two seconds to open its window, it’s likely doing more than you think. Windows Update and Defender are your two default safeguards—if a user finds them disabled without cause, they’ve been compromised.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

2 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

Ingénierie sociale via terminal — ClickFix et variantes 2026

  1. 1TerminalFix: fake Cloudflare CAPTCHA, real backdoor in your terminal31/08/2026
  2. 2PNG steganography + reverse tunnel: a new documented variant of stealthy attack01/09/2026
  3. 3Fake software installers: disabling Windows Update and weakening Defender before intrusion03/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information