You’re reading a legitimate website — an industry news site, a supplier, a local business directory — when a polished overlay appears: “Your browser is out of date. Update now to continue.” The logo is right, the wording is right, and the site itself is genuinely real. The download is not an update. It’s one of the most effective malware delivery tricks of the past several years.
How the scheme works
Criminal groups compromise thousands of legitimate websites — very often through vulnerable WordPress plugins or stolen admin credentials — and inject a small piece of code. That code checks each visitor’s browser and displays a matching fake update page: Chrome users see a Chrome update, Edge users see an Edge one. The best-documented operations are SocGholish (also called FakeUpdates, active since around 2018) and ClearFake (which emerged in 2023). Because the lure appears on real, previously trustworthy sites rather than dodgy ones, it reaches exactly the people who “would never fall for a scam”.
What the fake update actually installs
- Remote-access tools: SocGholish infections have been widely documented delivering the NetSupport remote-access tool, giving criminals hands-on control of the machine.
- Infostealers: ClearFake campaigns have delivered password-stealing malware that grabs saved logins, cookies and active sessions from the browser.
- A foothold for worse: security researchers have repeatedly traced ransomware incidents back to an initial fake-update infection — the access is often sold on to other criminal groups.
The one rule that defeats it
Modern browsers update themselves. Chrome, Edge and Firefox never ask you to download an update from a banner on a webpage — updates happen silently, or at most via a small prompt inside the browser’s own menu. Any webpage telling you to download a browser update is lying to you, every time, with no exceptions. That single sentence, taught to every staff member, defeats the entire scheme.
Defending your business
- Keep browser auto-updates on — a browser that’s already current makes the lure feel instantly wrong.
- Run EDR on every machine: the payload, not the download, is where this attack is reliably caught.
- Use DNS filtering — the infrastructure behind these campaigns is heavily tracked and widely blocked.
- If someone clicked and ran one: disconnect the machine, report it immediately, and reset passwords from a different device — speed matters far more than blame.
Fake updates succeed because they borrow trust from real websites and real habits. Break the habit — updates come from the browser, never the page — and the borrowed trust is worthless.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check