LIVE · cybersecurity feed
Live wire
scamhigh

Fake Microsoft security scans trick victims into uninstalling their antivirus

Scammers are operating fake Microsoft-branded websites that mimic security scans to trick users into uninstalling their antivirus software. These sites present fabricated security issues, falsely claim third-party antivirus is unsupported, and then guide victims toward a refund scam. The ultimate goal is to obtain personal information, banking details, and remote access to the victim's computer.

zeroday.news ·

A new refund scam is leveraging fake Microsoft-branded security scans to trick users into uninstalling their legitimate antivirus software, ultimately aiming to steal personal, banking, and remote-access information. Multiple websites, operating under names like SysScan, present convincing but fraudulent security scans that invariably conclude the user's computer has severe issues, falsely attributing these problems to their installed antivirus.

These scam sites claim that Windows no longer supports third-party antivirus products and instruct victims to uninstall them immediately. This assertion is false; Microsoft continues to support third-party antivirus solutions, and its own Microsoft Defender Antivirus can enter a passive state when another compatible product is installed, but this does not signify a lack of support.

The fake scans are designed to appear legitimate by reading some real browser data, such as operating system, screen size, and approximate location. However, the security conclusions drawn are entirely fabricated. For instance, the sites report issues like compromised browser sandboxes, inactive kernel page-table isolation, Rowhammer vulnerabilities, missing Trusted Platform Modules, WebRTC IP leaks, and thermally throttled processors—none of which a website can genuinely detect. One "security patch" check even generates a random number of days behind, producing different results with each scan.

Even genuine browser features are misrepresented as security risks. An encrypted connection might be flagged as a downgrade risk, and both enabled and disabled cookies are presented as warnings or failures. The "security score" is hardcoded to always fall between 13 and 30 out of 100, ensuring no computer ever "passes" the scan.

The instruction to uninstall antivirus software serves two critical purposes for the scammers: it removes security measures that could interfere with subsequent malicious activities, such as the installation of remote-access software, and it reveals which specific security product the victim was using from a list of 28 common antivirus solutions, including enterprise security software.

Following the fake scan, victims are prompted to fill out a customer information form. This form collects extensive personal details, including name, address, phone numbers, email, bank name, cryptocurrency username, and even the ID and password for a remote-access session, with a choice of 30 different remote-access tools. Intriguingly, the form also includes fields for "Agent ID," "Agent Name," and "Company," suggesting it is designed to be completed by an operator during a call, potentially while viewing the victim's screen. A field even asks if "explicit content" is involved, potentially to leverage embarrassment against victims.

Despite claims on the site that no data is sent or collected, the information entered into the form, along with agent and remote-access details, is bundled and sent directly to Telegram's bot API. This method makes the scam sites inexpensive to host and easy to abandon.

After submitting the form, victims are directed to a waiting page that plays a looping video of a man in an office, informing them that a "refund manager" will call within three to five minutes. This page is designed to keep the victim engaged and reassured that an official process is underway, setting the stage for the subsequent phone call where further financial and personal information is likely extracted.

Analysis of the website code reveals signs of AI generation, including extensive, self-narrating comments that explain the deliberate pacing of the scan and the terse tone of spoken lines. Some comments explicitly describe the deceptive elements, labeling blocks of invented findings as "fake" and genuine value checks as "exaggerated." One comment even falsely states that no data leaves the device, despite the function sending data to Telegram being present just a few hundred lines later. The fraud-specific elements, such as the US bank list and agent identifiers, appear to be integrated into a broader scanner template.

Users should be aware that legitimate websites cannot perform deep security scans of a computer, nor can they detect malware or memory issues. Microsoft continues to support third-party antivirus, and genuine refund processes never require uninstalling security software or installing remote-access tools. Any website making such claims should be immediately closed.

scamphishingfake antivirustech support scammicrosoft
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a vendor for evidence against a written baseline. TCG’s requirements for Trusted Platfor

nation-state

Cybersecurity jobs available right now: August 25, 2026

Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and court orders, and provide authorized subscriber, location, and call record information while acting as custodian of

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection […]

nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.