Ransomware disguises itself as Windows Update
Summary
This blueAPACHE post reports: Fantom, a recently identified ransomware, takes mimicking brands and applications to an entirely new level. Based on the open-source EDA2 ransomware project, Fantom camouflages itself as a critical Windows update. It concerns emPOWER Security, Managed Detection & Response, Offsite Backup as a Service. It names Microsoft in connection with the announcement. Published in 2016. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Services referenced | emPOWER Security, Managed Detection & Response, Offsite Backup as a Service |
| Named products or vendors | Microsoft |
Article
Devious new ransomware hides behind phoney Windows update to encrypt users’ files and demand ransom.
Fantom, a recently identified ransomware, takes mimicking brands and applications to an entirely new level. Based on the open-source EDA2 ransomware project, Fantom camouflages itself as a critical Windows update. It displays a fake update screen – which most Windows users will recognise – including the percentage counter.
Even with obvious shortcomings, this approach of appearing as a familiar and expected Windows function will likely help Fantom trick novice users into believing it is a legitimate update. The file properties have Microsoft copyright and trademark information to reinforce the appearance of legitimacy.
When executed, ‘criticalupdate01.exe’ appears as though Windows is performing a typical critical update, while in reality Fantom is encrypting user files in the background.
Once the encryption is complete, Fantom displays a ransom note named ‘Decrypt_Your_Files.HTML’. Typical ransom notes display the ransom amount in Bitcoins and an anonymous Tor web address by which to contact the attackers. Fantom instead asks victims to contact one of two email addresses for further instructions.
There is currently no means of decrypting Fantom, yet the risk level remains relatively low due to poor distribution models, a lack of bulk phishing and spam blasts, and the ransomware itself is somewhat poorly coded. Victims also have to download and execute the file themselves for this scam to work. This delivery method is a key shortcoming – Windows updates are not sent by email as program file (.exe) attachments.
Still, with the constant stream of innovation seen in the ransomware landscape, it may be only a matter of time before a more proficient variant appears on the scene.
The ransomware battle
Ransomware has steadily become the most problematic cyber threat of 2016 according to a report published by Kaspersky Lab earlier this year. The ease of launching an attack, combined with the willingness of victims to pay the ransom amount, makes this a highly lucrative business for cyber criminals looking for low-risk, high-reward schemes.
Ransomware attacks against organisations are particularly successful. It has been found that two-thirds of all companies that have been targeted will give in to the demands and pay ransoms to mitigate data loss and downtime. From a financial standpoint, the importance of having access to your sensitive and confidential data, when compared to the cost of ransom demands, make ransom payments appear to be an easy, quick and more viable solution.
However, there have been numerous instances of organisations learning the hard way that paying criminals is not a sustainable cyber security solution. For example, Ranscam simply deletes users’ files instead of encrypting them. Even when victims paid the amount demanded, they could never get their files back as it had already been permanently deleted.
Paying a ransom also sets a precedent. A successful ransomware attack encourages cyber criminals to repeatedly target and extort more money from their victims. It also spurs the creation of more robust variants of malware that are even more difficult to defend against.
What can you do?
When it comes to ransomware, prevention is better than cure. Once the ransomware gains access to your system – you are in remediation mode trying to limit exposure. You are faced with downtime, productivity loss, data loss and a potential branding and public relation nightmare should proposed regulatory changes demand disclosure. Mitigating your risk is a multi-pronged approach:
SECURITY MANAGEMENT
Securing against ransomware requires a holistic understanding of your security posture and having effective protection at every stage of the attack. It is not just about having the latest security products, but also designing your security solutions – from endpoint to firewalls – to share information and respond to threats proactively.
NEXT-GENERATION ENVIRONMENTS
Ransomware is constantly evolving to exploit new security holes and avoid detection; requiring the measures to protect against them to be just as agile and proactive. From firewalls to zero trust platforms, you have greater control over your technology environments than ever before, enabling you to design tailored solutions specifically to combat ransomware.
STAFF EDUCATION
Education is key to mitigate the risk of social engineering and phishing attacks. Hackers are increasingly targeting non-technical staff who are usually the least equipped to identify and protect against such attacks. When trained to be cautious and recognise a potential attack, your staff can become your first line of defence against ransomware.
DATA BACKUP
Ensuring that all your critical data is safely and frequently backed up can also help mitigate the impact of ransomware. Maintaining your data backups on external devices, storing them offline, and ideally offsite, lessens the impact of a ransomware attack.
BLOCK LISTS
Using a group policy across your organisation to prevent access to malicious domains is also an effective security measure against ransomware attacks. Most ransomware are launched using malicious links that direct users to a compromised site. A block list, such as the emPOWER secure recursive DNS service, can act as a gatekeeper for your organisation by blocking access to malicious domains and preventing users from inadvertently compromising the security of your data.
For more information on how you can help secure your organisations’ data and systems against ransomware attacks, contact the blueAPACHE account team.
Related
- emPOWER Security
- Managed Detection & Response
- emPOWER Security (pillar)
- Offsite Backup as a Service
- emPOWER Cloud (pillar)
Frequently asked questions
What does the article say the Fantom ransomware disguises itself as, and how does it operate?
The article says Fantom disguises itself as a critical Windows update, displaying a fake update screen with a percentage counter and Microsoft copyright and trademark information, while it encrypts user files in the background when the file "criticalupdate01.exe" is executed.
How does Fantom's ransom note differ from typical ransomware, according to the article?
The article says that unlike typical ransom notes that display a Bitcoin amount and a Tor address, Fantom's note, named "Decrypt_Your_Files.HTML", instead asks victims to contact one of two email addresses for further instructions.
What proportion of targeted companies does the article say give in and pay ransoms?
The article cites findings that two-thirds of all companies targeted by ransomware attacks give in to the demands and pay the ransom to mitigate data loss and downtime.
What mitigation measures does the article list against ransomware?
The article lists security management, next-generation environments such as firewalls and zero trust platforms, staff education, data backup, and block lists such as blueAPACHE's emPOWER secure recursive DNS service as a multi-pronged approach.
Is the information in this post still current?
No. It describes a specific 2016 ransomware variant, Fantom, and the threat landscape at that time; for blueAPACHE's current security services, see the emPOWER Security pillar page rather than this post.
Source
https://www.blueapache.com/blog/ransomware-disguises-itself-as-windows-update/
Knowledge Base
What is Fantom ransomware and how does it disguise itself?
Fantom is a ransomware identified in 2016 that is based on the open-source EDA2 ransomware project. It disguises itself as a critical Windows update, displaying a fake update screen—including a percentage counter—that most Windows users would recognize, in order to trick novice users into believing it is a legitimate update.
How does Fantom reinforce the appearance of legitimacy?
Fantom's file properties include Microsoft copyright and trademark information to reinforce its appearance as a genuine Windows update.
What happens when the Fantom ransomware file is executed?
When the file 'criticalupdate01.exe' is executed, it appears as though Windows is performing a typical critical update, while in reality Fantom is encrypting the user's files in the background.
How does Fantom demand ransom from victims, and how does this differ from typical ransomware?
Once encryption is complete, Fantom displays a ransom note named 'Decrypt_Your_Files.HTML'. Unlike typical ransom notes that display a Bitcoin ransom amount and an anonymous Tor address, Fantom instead asks victims to contact one of two email addresses for further instructions.
Is there a way to decrypt files encrypted by Fantom?
According to the article, there is currently no means of decrypting Fantom.
Why is the overall risk level of Fantom considered relatively low despite the threat?
The risk level remains relatively low due to poor distribution models, a lack of bulk phishing and spam blasts, and the ransomware itself being somewhat poorly coded. Victims also have to download and execute the file themselves, and since Windows updates are not sent by email as .exe attachments, this delivery method is a key shortcoming.
How significant a threat was ransomware in 2016 according to the article?
Ransomware had steadily become the most problematic cyber threat of 2016 according to a report published by Kaspersky Lab that year, driven by the ease of launching attacks and victims' willingness to pay ransoms.
What proportion of targeted organisations end up paying ransomware demands?
The article states that two-thirds of all companies that have been targeted by ransomware will give in to the demands and pay ransoms to mitigate data loss and downtime.
What example does the article give of paying a ransom not guaranteeing file recovery?
The article cites Ranscam as an example, which simply deletes users' files instead of encrypting them—meaning that even when victims paid the demanded ransom, they could never get their files back because the files had already been permanently deleted.
What multi-pronged measures does the article recommend to mitigate ransomware risk?
The article recommends a multi-pronged approach: security management (a holistic security posture with integrated protection), next-generation environments (agile, proactive protections like firewalls and zero trust platforms), staff education (training to recognise social engineering and phishing), data backup (frequent backups stored offline and offsite), and block lists (using group policy or services like blueAPACHE's emPOWER secure recursive DNS service to block access to malicious domains).
What is the emPOWER secure recursive DNS service mentioned in the article?
The emPOWER secure recursive DNS service is a block list solution offered by blueAPACHE that acts as a gatekeeper for organisations by blocking access to malicious domains and preventing users from inadvertently compromising the security of their data.
Who authored this blog post and when was it published?
The blog post was written by blueAPACHE and published on September 27, 2016, with a read time of about 5 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bef56ba2a604e908fa2_Windows-Update-Fantom.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf056ba2a604e909040_Windows-critical-updates.png
Windows Critical Updates
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf156ba2a604e909068_Fantom-Ransom-Note.png
Fantom Ransom Note
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)