Description

Fake IT support websites are distributing malicious PowerShell scripts under the guise of fixing common Windows errors, particularly the 0x80070643 error, which surfaced in January 2024 following a Windows update intended to address a BitLocker vulnerability (CVE-2024-20666). This error, mistakenly triggered by Windows Update, misleadingly indicates insufficient disk space in the Windows Recovery Environment (WinRE) partition. Exploiting user frustration, threat actors have established fake IT support sites like pchelprwizzards[.]com and pchelprwizardsguide[.]com. These sites lure users into executing PowerShell scripts or importing Windows Registry files as supposed solutions. However, these actions actually lead to the installation of Vidar, a malicious software designed to steal sensitive information. The PowerShell scripts, initially encoded in Base64, facilitate the download of additional scripts that install Vidar on the victim's system. Vidar operates by extracting a wide range of sensitive data, including credentials, credit card details, cookies, browsing history, cryptocurrency wallets, text files, and Authy 2FA databases. This harvested information is compiled into logs and then transmitted to the attackers' servers. Subsequently, the stolen data may be used for various malicious activities, such as financial fraud or sold on dark web platforms, exposing users to significant risks of account compromises and financial loss. To protect against these risks, it's crucial for users to download software and updates only from trusted sources. When dealing with the 0x80070643 error, if resizing the WinRE partition isn't feasible, consider using Microsoft's Show or Hide Tool to conceal the problematic KB5034441 update. Avoid relying on unverified fixes found online to reduce the risk of falling prey to deceptive IT support scams and the malware they distribute. These precautions are essential for safeguarding against potential threats and maintaining the security of your system.