A new wave of web-based scams is using counterfeit Microsoft-branded security scans to trick users into uninstalling their antivirus software. These fraudulent sites claim to perform thorough inspections, reporting alarming security failures and insisting that third-party antivirus solutions are unsupported by Windows. They gather basic browser information to create customized scan reports and aim to direct victims toward a fake refund process. Researchers have identified 11 related scam sites that falsely present themselves as Microsoft-affiliated security checks.
The scams do not require file downloads but instead use convincing websites, fabricated security scores, and customer information forms to build trust. The sites display unverifiable warnings about various system issues, and many scan results are hard-coded rather than generated by actual assessments. The security score is intentionally low, ensuring no favorable results. The most harmful instruction is to uninstall existing antivirus software, despite Windows supporting third-party solutions.
The scam sites request extensive personal information through a form, which is then transmitted to Telegram. Victims are promised a call from a refund manager, during which remote-access software can be used to gain control of their computers. Similar schemes have exploited legitimate remote monitoring tools for fraudulent activities. Individuals who grant access should disconnect from the internet, remove the remote-access tool, and secure their accounts.
Indicators of compromise include specific IP addresses and domains associated with the scam sites, such as detectsysscanner[.]at and detectsysscanner[.]com.