Malicious Software Installers Spread, Disabling Windows Update and Weakening Microsoft Defender
A growing number of malicious software installers have been discovered to not only install malware on victims’ computers but also disable Windows Update and compromise Microsoft Defender’s effectiveness. These fake installers, designed to look like legitimate software packages, are being distributed via compromised websites, phishing emails, and other vectors, putting millions of users at risk.
The affected software includes popular titles such as Adobe Acrobat Reader, Mozilla Firefox, and 7-Zip, among others. The malicious installers use a technique called “software bundling” to quietly install malware on the victim’s system alongside the actual software they requested. Once installed, these programs disable Windows Update, preventing users from receiving critical security patches and updates that protect against known vulnerabilities.
But that’s not all – the malware also compromises Microsoft Defender, rendering it ineffective against various types of threats. This is a concerning trend, as Microsoft Defender is one of the most widely used antivirus solutions on the market, relied upon by millions of users worldwide. By disabling it, attackers can freely exploit vulnerabilities in Windows without fear of detection.
The reason behind this dual attack lies in the fact that many malware programs are designed to evade detection by security software like Microsoft Defender. By installing themselves alongside legitimate software and then compromising its effectiveness, malicious actors can ensure their malware remains active on infected systems. This also enables them to carry out more sophisticated attacks, such as lateral movement within a network or data exfiltration.
The widespread distribution of these fake installers is likely facilitated by the fact that many users are not cautious when downloading software from the internet. With so many legitimate software packages available online, it can be difficult for individuals to distinguish between genuine and malicious downloads. This highlights the importance of practicing safe browsing habits, including only installing software from trusted sources and carefully reviewing system changes after installation.
To avoid falling victim to these malicious installers, users should exercise extreme caution when downloading software from the internet. Stick to reputable websites and avoid clicking on suspicious links or opening attachments from unknown senders. Always verify the authenticity of a software package by checking its digital signature and ensuring it matches the expected publisher. By taking these precautions, you can significantly reduce your risk of being targeted by malicious installers and keep your systems secure.
Source: The Hacker News — 2026-09-02