A new web-based scam uses counterfeit Microsoft-branded security scans to trick users into uninstalling their antivirus software. The scam websites claim to conduct thorough inspections, reporting false security failures and asserting that third-party antivirus products are unsupported by Windows. They gather basic information from users' browsers to create customized scan reports and aim to mislead victims into a fraudulent refund process. Eleven related scam sites have been identified, all hosted on the same server, using similar branding and misrepresenting themselves as legitimate Microsoft security checks.
The scam sites display alarming warnings about various security issues that a website cannot genuinely verify. Many scan results are hard-coded, and the security score is limited to a range between 13 and 30 out of 100. The most harmful instruction is to uninstall existing antivirus software, which is not required by legitimate companies. After the fake scan, victims are asked to provide extensive personal information through a form, which is then sent to Telegram via its bot API. They are promised a follow-up call from a refund manager, during which scammers may gain remote access to the victim's computer.
Indicators of compromise include an IP address (157.230.180.90) associated with the scam sites and multiple scam domain names, such as detectsysscanner[.]at and detectsysscanner[.]com.