A new online scam is exploiting fake security checks branded with Microsoft logos to alarm users into removing their antivirus software. These deceptive sites claim to perform device inspections, falsely reporting critical security errors and asserting that third-party antivirus programs are unsupported by Windows. The urgency of these messages is crafted to feel personal and immediate.
How the Scam Operates
The fraudulent websites gather basic browser data such as screen size and device specifics, using this information to create a scan report that appears personalized to the visitor. The ultimate aim is to lure victims into a sham refund process. According to Malwarebytes, which shared its findings with Cyber Security News, 11 related sites were identified on the same server.
Each of these sites employs similar ‘SysScan’ branding, misleading users to believe they are undergoing a legitimate Microsoft security check. The sites falsely claim that antivirus software is the cause of various system issues, misleading users into removing their digital protections.
Deceptive Techniques and Threats
Unlike typical scams that start with a file download, this operation utilizes a sophisticated website, fake security scores, customer information forms, and promised phone calls to gain user trust. By the time scammers solicit remote access or banking information, victims may be convinced they are engaged in a legitimate support process.
These sites present unverifiable warnings about browser isolation, memory flaws, firmware settings, Windows patches, and processor performance. However, a website cannot genuinely scan a computer’s intricate components or accurately assess antivirus effectiveness.
Risks and Protective Measures
The scam’s most harmful suggestion is the directive to uninstall antivirus software. While Windows can place Microsoft Defender Antivirus in a passive state alongside compatible third-party products, Windows continues to support these antivirus solutions. Reports on tools that disable Windows Defender highlight why attackers prioritize weakening endpoint protection.
Users should be skeptical of any webpage claiming to perform a comprehensive computer security scan. Legitimate companies do not demand the removal of protective software as part of support, refunds, or security checks. Closing such pages when they present only negative results and demand immediate action is the safest approach.
Immediate Actions for Victims
The scam progresses by presenting a form that collects extensive personal data, including names, addresses, emails, bank details, and remote-access credentials. It also asks for an agent ID and company name, implying an operator may assist victims during a phone call. Victims are given the choice of 30 remote-access tools, enabling scammers to control the computer under the guise of processing a refund.
Once information is submitted, it is transmitted to Telegram via its bot API, leading victims to a page claiming a refund manager will call shortly. Meanwhile, an office video loop attempts to impart a sense of legitimacy. If remote access has been granted, disconnecting the device from the internet, removing the tool, reinstalling antivirus software, and running a full scan are crucial steps.
Anyone who accessed banking information should contact their bank immediately using a phone number found independently and change their email and banking passwords from a trusted device. Prompt reporting of such incidents can mitigate financial loss or further account compromise.
