Cyber Security News

New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials

A new campaign has emerged that weaponizes Microsoft’s familiar branding to lure unsuspecting users into a sophisticated tech support scam.

Victims receive a seemingly legitimate email, complete with Microsoft’s official logo, claiming there is an important financial transaction or security alert requiring immediate attention.

The message prompts recipients to click a link under the guise of confirming identity or resolving an urgent issue.

Cofense analysts noted that the threat actors have refined their social engineering tactics by combining payment lures with deceptive UI overlays to maximize impact.

Upon clicking the link, users are redirected through a faux CAPTCHA challenge designed to mimic a trusted verification process.

Redirect Page (Source -Cofense)

When the victim completes the verification, they are led to a landing page where the browser appears locked by multiple pop-up windows styled after genuine Microsoft security alerts.

Email Body (Source -Cofense)

The attacker’s goal is to create a sense of panic, convincing the user that their system has been compromised beyond normal functionality.

In many cases, the scam culminates in a displayed support phone number claiming to be Microsoft’s helpline.

When the victim dials, they connect to a malicious actor posing as a support technician.

Under the pretext of resolving the infection, the scammer persuades the target to divulge their Microsoft account credentials or install a remote desktop tool to “repair” the system, thereby granting full access to the attacker’s infrastructure.

Infection Mechanism

The infection begins with a list of observed URLs that serve as redirectors and payload hosts. The initial redirector domains include:

hxxps://alphadogprinting.com/index.php?8jl9lz
hxxps://amormc.com/index.php?ndv5f1

These URLs funnel victims through a CAPTCHA page before landing on the malicious overlay server. The payload domains, such as:

hxxps://my.toruftuiov.com/9397b37a-50c4-48c0-899d-f5e87a24088d
hxxps://deprivy.stified.sbs/proc.php

host the scripted overlays that manipulate the DOM to disable mouse control and display counterfeit alerts.

The browser lock is purely illusory and can be dismissed by pressing the ESC key, but few victims discover this before contacting the attacker.

By blending trusted logos with multiple redirect stages and UI deception, this campaign exemplifies an evolving threat that leverages brand familiarity to facilitate credential theft.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago