A new ongoing malicious tech support scam has been identified recently that involves the development of several phishing websites that are being operated by the Threat Actor.
All of these phishing sites display a fake Windows Defender alert and, in order to make the scenario appear more legitimate, they pretend to be Microsoft support sites.
Since September 2022, more than 50 phishing websites have been discovered. While the following IP address has been identified to be associated with these websites and this address has been found to be located in India:-
Moreover, as a result of an analysis of tech support scams, security researchers have been able to find out that 85% of IPs that are used by threat actors to commit frauds like this originate from India.
This scam is similar to other technical support scams where users receive the URL of the scam website via email or SMS message. In this scam users received the following phishing URL:-
The user will see several popup windows in which they will get warnings claiming:-
“This computer has been blocked due to illegal activity.”
The fake website window also plays an audio message that says “important security message” until the user closes the website with the intention of stopping it.
Upon opening the URL, a pop-up is displayed that states “Quick Scan” and then a fake scan appears, stating that threats have been detected on the user’s computer.
Upon doing that, it displays a fake Threat Scan result with a number of key details, as follows:-
The site then informs the victims of the presence of Trojan spyware on their computers, and they can take action accordingly. There was also a compromise of sensitive data involved in this incident.
In this fake sensitive data compromise alert the site claims that the following data are compromised:-
Next, the scammers show a “Windows Defender Security Center” pop-up to the victim in which they ask to call a support technician by dialing the number provided in the pop-up window.
Apart from this, it has also been identified that the operators of these tech support scams are also targeting iPhone devices.
Listed below are some of the most important security practices that will help you to create the first layer of defense against such scams and scammers:-
Cyber Attack with Zero Trust Networking – Download Free E-Book
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…