Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A recent investigation has unveiled a network of fraudulent websites masquerading as Microsoft, employing deceptive “security scans” to manipulate unsuspecting users. These sites, branded under the name SysScan, claim to evaluate the effectiveness of antivirus software, but their conclusions are predetermined and misleading. Victims are coerced into uninstalling legitimate antivirus products, revealing sensitive personal and banking information, and granting remote access to their computers.

SysScan’s websites assert that a user’s computer is at risk due to the false premise that Windows no longer supports third-party antivirus solutions. This assertion is inaccurate; Microsoft Defender Antivirus is designed to work alongside non-Microsoft security products, often entering a passive state when a registered third-party antivirus is active.

Researchers have pinpointed eleven distinct domains associated with SysScan, all hosted on a single server. While the branding may differ, the operational flow remains consistent: victims are presented with a convincing scan, informed of severe yet fabricated security issues, and instructed to disable their antivirus software. This sets the stage for a subsequent social engineering attack conducted over the phone.

The fraudulent scanner collects various browser-accessible data, including user-agent strings, display resolutions, and device specifications. However, the alarming security verdicts it generates do not rely on this information. Instead, the code contains 50 static findings categorized under “fake checks,” which do not accurately assess system-level controls or antivirus health.

One particularly dubious result, indicating a lag in system patches, is generated from a random number, leading to inconsistent outcomes upon repeated scans. The scoring mechanism further entrenches the deception, as results are artificially constrained to a range of 13 to 30 out of 100, rendering a passing score impossible.

Microsoft Refund Scam

Normal browser behaviors are misrepresented as security risks; for instance, enabled cookies are flagged as warnings while disabled cookies are deemed failures. Claims of compromised browser sandboxes and other technical vulnerabilities are fabricated to instill fear and prompt action.

The most perilous instruction within this scheme is the recommendation to uninstall antivirus software, which significantly weakens the victim’s defenses. This step also reveals the specific antivirus product in use, making it easier for scammers to target their efforts.

The form used by these scammers allows operators to select from 28 antivirus products, including enterprise-level security tools, indicating that the operation may also be targeting business users and workplace devices.

Malwarebytes researchers have noted that this scam exploits a legitimate feature of Windows: when a compatible third-party antivirus is installed, Microsoft Defender Antivirus may temporarily step aside to prevent conflicts. However, this does not imply that Windows has ceased supporting third-party security solutions.

After presenting the fabricated scan results, the sites request a plethora of personal information, including names, addresses, phone numbers, email addresses, refund amounts, bank details, and even remote-access session credentials. Victims are given the option to choose from 30 different remote-access tools, further complicating the situation.

Additionally, the form includes fields for Agent ID, Agent Name, and Company, suggesting a design intended for call-center operators who may assist victims through the process or monitor their screens. The data submitted is aggregated and sent directly to Telegram via its bot API, streamlining the operation and making it cost-effective and easily disposable when domains are reported or blocked.

Despite claims of not collecting data, these pages interact with external IP and geolocation services, exfiltrating submitted information. If a victim has installed remote-access software or if a scammer has gained control over their device, it is crucial to disconnect from the internet, remove any unauthorized tools, run a trusted antivirus scan, change passwords from a secure device, and reach out to their bank or payment provider.

A subsequent waiting page promises that a “refund manager” will call within a few minutes, marking a transition to the next phase of the fraud. Users are advised to close any webpage that claims to conduct a comprehensive security assessment through their browser, as legitimate refund processes will never require the removal of antivirus software, remote access, or sensitive banking information.

Indicators of Compromise

IOC Type Value
IPv4 Address / Hosting 157.230.180.90
Domain detectsysscanner[.]at
Domain detectsysscanner[.]com
Domain detectsysscanner[.]de
Domain detectsysscanner[.]in[.]net
Domain detectsysscanner[.]xn--q9jyb4c
Domain detsysscanner[.]com
Domain detsysscanner[.]de

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Tech Optimizer
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud