Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Exploit Fake Avast Site for Credit Card Data

Cybercriminals Exploit Fake Avast Site for Credit Card Data

Posted on February 25, 2026 By CWS

Cybercriminals have developed a new phishing campaign, leveraging the trusted brand of the cybersecurity company, Avast, to steal sensitive financial information. This scheme involves a fake website that convincingly mimics Avast’s official portal to trick users into providing their credit card details.

Deceptive Tactics Used in Phishing

The fraudulent website is meticulously designed to resemble the legitimate Avast site, utilizing official logos and color schemes to establish credibility instantly. Victims are shown a fictitious transaction of €499.99, prompting urgent action due to a misleading cancellation deadline of 72 hours, while also stating transactions older than 48 hours are irreversible. This contradiction is often missed by users anxious about the financial loss.

The attackers enhance the site’s authenticity by embedding the real Avast logo from the company’s content delivery network. The fixed transaction amount appears realistic for a software subscription, urging users to act quickly.

Technical Aspects of the Scam

Malwarebytes researchers have discovered that the scam utilizes dynamic JavaScript to insert the current date into the fake transaction record, making the fraudulent charge seem recent. This technique is designed to maximize the shock value for unsuspecting visitors, whether they are actual Avast customers, former subscribers, or individuals concerned about potential identity theft.

The campaign’s broad target audience includes opportunists attempting to claim non-existent refunds, as no authentication is required to proceed to the data collection forms.

Data Collection and User Manipulation

The scam’s technical framework efficiently validates and exfiltrates user data while simulating a support interaction. Once victims provide their contact information, they are prompted to enter their full credit card details, which are verified using the Luhn algorithm to ensure validity before being sent via a POST request.

A live chat feature is also embedded, allowing attackers to interact with hesitant users and encourage them to complete the form. After the data is stolen, users are redirected to a confirmation page, further misleading them by suggesting the removal of security tools that could alert them to the fraud.

Protecting Against Phishing Threats

To safeguard against such threats, users should be aware that legitimate companies never request full credit card numbers for refunds. If a suspicious charge arises, visit the company’s official site directly rather than clicking links in unsolicited messages. Those who have provided their details should immediately contact their bank to cancel the compromised card and dispute charges.

It is also essential to update passwords for any associated accounts and use detection tools like Scam Guard for suspicious messages. Keeping operating systems and applications up-to-date and running comprehensive security scans can help prevent further risks.

Cyber Security News Tags:Avast, credit card theft, cyber attack, Cybersecurity, fake websites, fraud prevention, identity theft, online security, phishing scam, scam detection

Post navigation

Previous Post: UK Imposes $20M Fine on Reddit for Child Data Breaches
Next Post: Cortex XDR Vulnerability Enables Covert Command Channels

Related Posts

Rising Cyber Threats Challenge Defense Sector Security Rising Cyber Threats Challenge Defense Sector Security Cyber Security News
SonicWall Confirms No New SSLVPN 0-Day Ransomware Attack Linked to Old Vulnerability SonicWall Confirms No New SSLVPN 0-Day Ransomware Attack Linked to Old Vulnerability Cyber Security News
Elastic Defend for Windows Vulnerability Let Attackers Escalate Privileges Elastic Defend for Windows Vulnerability Let Attackers Escalate Privileges Cyber Security News
WaterPlum’s New Malware Threatens VSCode Security WaterPlum’s New Malware Threatens VSCode Security Cyber Security News
15,200 OpenClaw Systems at Risk Due to Internet Exposure 15,200 OpenClaw Systems at Risk Due to Internet Exposure Cyber Security News
PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Adobe Reader Flaw Patched After Months of Exploitation
  • Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation
  • CPUID Breach: STX RAT Spread via Compromised Downloads
  • OpenAI Urges macOS Users to Update Apps Amid Security Threat
  • Google Enhances Gmail with Mobile End-to-End Encryption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Adobe Reader Flaw Patched After Months of Exploitation
  • Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation
  • CPUID Breach: STX RAT Spread via Compromised Downloads
  • OpenAI Urges macOS Users to Update Apps Amid Security Threat
  • Google Enhances Gmail with Mobile End-to-End Encryption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark