Catch Of The Week: The ‘Security Scan’ That Wants You Defenseless

Researchers at Malwarebytes have recently dissected a network of deceptive websites operating under the guise of a service called “SysScan,” which masquerades as a Microsoft security checkup. Users often stumble upon these sites through various means—be it a search result that appears legitimate, a browser hijacking pop-up, or an unsolicited email regarding a subscription they have no recollection of purchasing.

How the Scam Works

Upon landing on the site, visitors are greeted with familiar Microsoft branding and a progress bar that suggests their computer is undergoing a thorough scan. However, the reality is far less benign; the site does not perform any actual scanning. Instead, it collects a few harmless details that browsers typically share, such as the operating system, screen size, and approximate location. These innocuous facts are then manipulated and presented as alarming findings.

The researchers uncovered that the site contains fifty blocks of pre-written text, categorized as fake security checks. Among the fabricated alerts are claims like “browser sandbox is compromised” and “your memory is vulnerable to Rowhammer.” None of these assertions hold any truth; they are simply hard-coded messages designed to instill fear in users.

Moreover, the so-called “security score” generated for users is also predetermined, landing between 13 and 30 out of 100, regardless of the actual security status of the user’s machine. Whether one is operating a fully updated system or an outdated laptop, the outcome is the same: a message of impending danger.

Once the user is sufficiently alarmed, the site reveals its true intention. It falsely claims that Windows no longer supports third-party antivirus software, urging users to uninstall their existing protections. This misleading statement is crafted to sound credible by distorting the truth; while it is accurate that Windows Defender becomes inactive when a third-party antivirus is installed, this does not imply that the latter is unsupported or ineffective.

This tactic serves a dual purpose for the scammers. Not only does it encourage users to remove their antivirus software—leaving them vulnerable—but it also provides the scammers with a list of specific antivirus products that users had installed. With this information, they can tailor their next steps more effectively.

Following this, users are prompted to fill out a form requesting personal details, banking information, and even cryptocurrency account credentials. The layout of the form suggests that it is intended for a “technician” to complete while guiding the user over the phone. Any information entered is sent through a Telegram bot, and a waiting screen indicates that a “refund manager” will call within minutes, furthering the deception.

To avoid falling victim to such scams, users need not memorize domain names. Researchers have traced eleven of these fraudulent sites back to a single server, with names like detectsysscanner and techsysscanner. These names are easily changeable, but the deceptive behavior remains consistent.

Indicators of a Scam:

  • Running a “scan” from a browser tab that identifies serious issues.
  • Instructing you to uninstall or disable your antivirus software.
  • Requesting the installation of remote-access software for “fixing” issues.
  • Asking for banking details, card numbers, or cryptocurrency information for a refund.
  • Presenting countdowns, phone numbers, or promises of callbacks.

It’s crucial to remember that Microsoft does not initiate cold calls, nor does it scan computers through web pages. No reputable company would request sensitive information or remote access to issue a refund.

If You’ve Already Engaged:

Rather than dwelling on embarrassment, which is a common reaction, it’s essential to act swiftly. Disconnect the affected machine from the internet, uninstall any remote-access tools that may have been installed, and reinstall your antivirus software. Update it and run a comprehensive scan. Contact your bank using the number printed on your card, not one provided by the scammers. Change your passwords from a secure device, and report the incident to the FTC and FBI to aid in tracking and dismantling these operations.

A Guiding Principle:

One fundamental rule applies universally in this realm: legitimate security software will never instruct you to reduce your security measures.

Stay vigilant and informed to avoid falling prey to such scams.

Tech Optimizer
Catch Of The Week: The ‘Security Scan’ That Wants You Defenseless