Threat actors set up the spoofed domain windows-upgraded[.]com to mimic Microsoft's Windows 11 upgrade page and trick Windows 10 users into downloading a malicious archive, Windows11InstallationAssistant.zip, hosted via a Discord CDN. The lure appeared shortly after Microsoft expanded Windows 11 availability, targeting users eager to upgrade, including those unable to obtain the OS through official channels. Researchers said the downloaded package contained an unusually large padded executable that expanded to about 751 MB, a tactic likely intended to evade sandbox analysis and security scanning.
When launched, the fake installer executed a multi-stage chain using PowerShell and cmd.exe, paused for 21 seconds, fetched a disguised payload named win11.jpg from a remote server, reversed the file into a DLL, and loaded RedLine Stealer. The malware collected host, software, and hardware details, along with browser passwords, autocomplete and credit card data, and cryptocurrency wallet files, then contacted a command-and-control server at 45.146.166[.]38:2715 over TCP. HP linked the operation to an earlier fake Discord installer campaign based on shared registrar, DNS infrastructure, delivery methods, and use of the same malware family.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
A malicious actor registered windows-upgraded[.]com to impersonate Microsoft's Windows 11 site and distribute malware. HP tied the registration to the same day Microsoft announced the final phase of the Windows 11 upgrade rollout.
In December 2021, attackers ran a RedLine Stealer campaign using the fake domain discrodappp[.]com to distribute malware disguised as a Discord installer. HP said the later Windows 11 lure shared registrar, DNS infrastructure, delivery style, and malware family with this earlier activity.
By the time the campaign was reported publicly, the observed malware distribution site was no longer online. Researchers warned the operators could quickly register a new domain and resume the activity.
HP Wolf Security publicly documented the fake Windows 11 upgrade campaign, including the oversized padded executable, the win11.jpg payload retrieval, and the RedLine C2 at 45.146.166[.]38:2715. The report also linked the activity to the December 2021 fake Discord installer campaign.
Threat actors used the fake windows-upgraded[.]com site to trick Windows 10 users into downloading Windows11InstallationAssistant.zip from Discord's CDN, which ultimately installed RedLine Stealer. The infection chain used a padded executable, PowerShell and cmd.exe, then fetched a disguised payload and loaded it as a DLL that connected to a C2 server.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.