Listen to this Post
A New Scam Built Around Familiar Microsoft Branding
Cybercriminals are once again exploiting one of the most powerful weapons in social engineering: fear.
A new refund scam is using fake Microsoft-branded security scanning websites to convince Windows users that their computers are dangerously compromised. The websites imitate legitimate security tools, perform what appears to be a detailed system inspection, and then present victims with alarming warnings about antivirus software, Windows security, kernel protections, memory safety, and network privacy.
The technical appearance is convincing. The conclusions are not.
Instead of genuinely detecting malware or vulnerabilities, the scam pages manufacture security problems and use them to push victims toward a second stage of fraud: removing legitimate antivirus protection and providing sensitive personal, financial, and remote-access information to supposed refund agents.
Researchers identified at least 11 related scam websites hosted on the same server, demonstrating that this is not simply an isolated malicious webpage. It is part of a broader fraud infrastructure designed to make victims believe that a serious security problem has been discovered on their computers.
The First Warning Sign: A Security Scan That Wants You to Panic
The scam begins with a website that presents itself as a security scanner.
Names such as SysScan are used to create the impression of a professional diagnostic service. The visitor is encouraged to believe that the page can examine their Windows computer and determine whether their antivirus product is functioning correctly.
The website then collects information that a normal browser can legitimately expose, including the operating system, screen resolution, available memory, processor count, browser capabilities, permissions, and certain network-related information.
That information is real.
The security conclusions drawn from it are not.
This distinction is critical because the scam uses genuine browser information as a foundation for completely fabricated technical findings. By displaying real characteristics of the victim’s device, the website makes the fake diagnosis appear personalized and therefore trustworthy.
The Microsoft Claim That Should Immediately Raise Suspicion
One of the most dangerous claims made by the scam is that Windows no longer supports third-party antivirus software.
That statement is false.
Windows continues to support third-party security products, and users are not required to uninstall legitimate antivirus software simply because a suspicious website tells them to do so.
The scam deliberately reverses the normal security relationship. Instead of encouraging users to strengthen their protection, it tries to convince them that their protection itself is the problem.
That is a major psychological turning point.
Once a victim removes an antivirus product, the computer may become less protected precisely when the scammers are preparing to gain deeper access to it.
The Fake Scan Looks Technical Because It Uses Real Browser Data
Modern scam websites do not necessarily need sophisticated malware to appear convincing.
JavaScript running inside a browser can gather a surprising amount of information about the environment in which it is executing. A malicious website can learn details such as the browser type, operating system characteristics, display dimensions, processor availability, memory-related information exposed by the browser, supported APIs, permissions, and various browser capabilities.
Scammers can then place those details inside a visually impressive dashboard.
The result looks like a security product.
But a webpage is not automatically capable of performing the deep inspection that its interface claims to perform.
What the Fake Scanner Cannot Actually Prove
A conventional website cannot simply inspect a Windows installation and reliably determine whether the system contains sophisticated malware, whether firmware settings are secure, whether kernel-level protections are enabled, whether every Windows security update is missing, or whether the computer is vulnerable to a specific hardware attack.
Yet the fraudulent scanner claims to detect precisely these kinds of problems.
The page may warn that the browser sandbox has been compromised, that system memory is exposed to Rowhammer attacks, that kernel protections are disabled, that the machine lacks a Trusted Platform Module, or that WebRTC is leaking a local IP address.
These warnings sound highly technical.
That is exactly why they work.
Hardcoded Threats Create the Illusion of Intelligence
Researchers found that many of the warnings displayed by the scam are hardcoded into the website.
In other words, the website is not necessarily discovering a problem on the victim’s computer. It is simply displaying a predetermined warning.
One alleged Windows patch warning is particularly revealing because the number of supposedly missing updates can be randomly generated.
The implication is disturbing but straightforward: the result can change even though the underlying computer has not changed.
A genuine vulnerability scanner should produce findings based on evidence.
A fraudulent scanner produces findings based on persuasion.
The Security Score Is Designed to Fail
The fake scanner also manipulates its security score.
The underlying code restricts the displayed result to a range of approximately 13 to 30 points out of 100.
That means the victim is effectively guaranteed to receive a frighteningly low score.
There is no meaningful diagnostic process behind the number. It is a psychological device.
A score of 18 out of 100 immediately communicates danger to a nontechnical user. The victim may not know what a TPM is or understand Rowhammer, but they understand that a score of 18 means “bad.”
This is an important lesson in modern online fraud: numbers can create credibility even when the underlying measurement is meaningless.
Fear Is the Product Being Sold
The scam does not need victims to understand the technical terminology.
It only needs them to feel that something is seriously wrong.
A normal user who sees warnings about kernel security, memory exposure, browser sandbox compromise, missing patches, and network leaks may conclude that their computer has been hacked.
The more complicated the terminology becomes, the less likely a victim is to challenge the diagnosis.
This is social engineering disguised as cybersecurity.
The Antivirus Removal Trick
After generating the fake warnings, the scam tells the victim that their existing antivirus software is responsible for the problems.
This is one of the most dangerous elements of the operation.
The victim is encouraged to remove legitimate security software at precisely the moment when they are becoming emotionally vulnerable and potentially preparing to interact with an unknown “support” or “refund” representative.
The scammers therefore attempt to create a security vacuum.
First, they convince the victim that the machine is unsafe.
Then, they persuade the victim to weaken its defenses.
Finally, they attempt to obtain information or remote access.
From Fake Security Scan to Fake Refund
The second stage of the scam is presented as a refund process.
After the fake scan, visitors encounter a form requesting a surprisingly large amount of information.
The requested fields reportedly include:
Full name
Address
Phone number
Email address
Bank name
Refund amount
Cryptocurrency username
Antivirus product
Remote-access software information
Remote-access IDs and passwords
Agent ID
Agent name
Company information
This is far beyond what a legitimate security scan should need.
A security website has no legitimate reason to demand remote-access credentials simply because it has supposedly detected antivirus problems.
That alone should be treated as a critical warning sign.
The Remote-Access Component Makes the Scam More Dangerous
The ability to collect remote-access information changes the threat considerably.
Victims can reportedly select from roughly 30 remote-access applications. This strongly suggests that the scammers are preparing for a live interaction in which a fraudulent support agent guides the victim through the next stage.
Remote-access software itself is not inherently malicious.
The problem is who controls the session and why.
A legitimate technician may use remote-support software under carefully controlled circumstances. A stranger who contacts you after a random website claims your computer is infected is a completely different situation.
Once remote access is granted, the attacker may potentially view files, manipulate applications, change settings, install software, access browser sessions, or attempt to steal additional credentials.
Agent Details Reveal the Human Fraud Operation
The presence of fields such as Agent ID, Agent Name, and Company is another significant clue.
These fields suggest that the refund form may be designed to support a telephone-based scam workflow.
The victim may first visit the fraudulent website, become frightened by the fake scan, and then communicate with a supposed refund representative.
The representative can then guide the victim through the form while simultaneously persuading them to install or provide access through a remote-management application.
This creates an illusion of a structured customer-service operation.
In reality, it may be a carefully scripted fraud chain.
The
What makes this campaign particularly interesting is the combination of technical deception and human manipulation.
The website does not need to discover a sophisticated vulnerability.
It needs to convince the victim that it has.
The scanner interface establishes authority.
The device-specific information creates personalization.
The fabricated warnings create fear.
The low security score creates urgency.
The antivirus-removal instruction weakens defenses.
The refund form collects sensitive information.
The remote-access section creates the possibility of direct system compromise.
Each step prepares the victim for the next one.
Fake Security Websites Are Becoming More Convincing
The broader trend is important for cybersecurity professionals.
Security scams are increasingly adopting the visual language of legitimate security products. Dashboards, progress bars, threat counters, vulnerability scores, warning banners, animated scans, and technical terminology can all be generated relatively easily with modern web technologies.
A polished interface should therefore never be treated as proof of legitimacy.
The question should always be: What evidence is the website actually capable of collecting?
If a page claims to have scanned the Windows kernel but is operating entirely inside a normal browser tab, skepticism is justified.
Why Browser Information Is So Useful to Scammers
Browser-exposed information gives attackers enough material to create a convincing illusion.
Knowing that a visitor uses Windows, has a particular screen resolution, possesses several logical processors, and supports certain browser features allows the scam page to customize its presentation.
For example, a fake scanner can display the victim’s actual operating system and processor count beside fabricated security warnings.
The victim sees information they recognize as correct.
That creates a dangerous cognitive shortcut: if some information is accurate, the victim assumes everything else must also be accurate.
That assumption is exactly what the scammers want.
The Fake Rowhammer Warning
The reference to Rowhammer is a good example of technical intimidation.
Rowhammer is a real class of hardware-related memory attacks. But mentioning a legitimate security concept does not mean a website has actually tested the victim’s hardware for susceptibility.
Scammers can take real cybersecurity terminology and insert it into a completely fraudulent diagnosis.
This technique works because many users cannot easily distinguish between “a real technology exists” and “this website has proven that your computer is vulnerable to it.”
Those are two very different claims.
The Fake TPM Warning
The same strategy applies to Trusted Platform Module warnings.
TPM technology is genuinely important to modern Windows security, particularly for features involving hardware-backed security and Windows 11 requirements.
But a website displaying a message claiming that your computer has “no TPM” does not automatically prove that the machine lacks one.
A legitimate diagnostic utility would use appropriate operating-system mechanisms and trusted local software to verify hardware security information.
A browser page cannot simply be granted that level of authority because it looks official.
The WebRTC IP Leak Warning
WebRTC-related privacy warnings can also sound frightening.
A browser may expose certain network-related information depending on the environment and browser configuration, but presenting this as proof that the entire computer has been compromised is misleading.
The scam takes a legitimate technical subject and exaggerates it into an emergency.
This is a common pattern in scareware campaigns.
The
Researchers identified at least 11 scam sites hosted on the same server.
The infrastructure reportedly includes the following indicators:
IP Address: 157.230.180.90
Domain: detectsysscanner[.]at
The domain has been intentionally defanged to reduce the risk of accidental navigation.
Security teams should treat these indicators as starting points for investigation rather than as the only artifacts worth searching for. Related domains, URLs, certificates, hosting relationships, DNS history, scripts, page assets, and redirect infrastructure may reveal additional components of the campaign.
Deep Analysis: How to Investigate the Scam Safely
Security analysts should never interact with suspicious scam infrastructure from a production workstation merely to “see what happens.”
A safer approach is to collect indicators and investigate them through controlled threat-intelligence systems, sandbox environments, SIEM telemetry, DNS logs, and endpoint data.
For a known domain or IP, defenders can begin with basic defensive searches such as:
Search DNS/security logs for the suspicious domain
grep -Ri "detectsysscanner.at" /var/log/
Search proxy logs for the suspicious IP
grep -Ri "157.230.180.90" /var/log/
Search common web logs for related requests
grep -RiE "detectsysscanner|157.230.180.90" /var/log/nginx /var/log/apache2 2>/dev/null
For organizations using a SIEM, a generic detection concept might look like:
(domain == “detectsysscanner.at”)
OR
(destination_ip == “157.230.180.90”)
The exact syntax should be adapted to the organization’s SIEM.
Browser Investigation Requires More Than a Screenshot
A screenshot of a scam page is useful, but it is not enough for threat hunting.
Analysts should preserve the complete URL, timestamp, referring URL, DNS information, HTTP headers where appropriate, downloaded scripts, redirect chains, and relevant browser telemetry.
JavaScript should also be examined for hardcoded warning strings, random-number generation, fingerprinting logic, remote-access software lists, form submission endpoints, and infrastructure references.
The objective is to understand the entire fraud chain rather than merely identify the landing page.
Endpoint Telemetry Can Reveal the Second Stage
If a user interacted with the scam, endpoint telemetry becomes particularly important.
Security teams should investigate whether the user downloaded remote-access software, launched a remote-support application, created a new process shortly after visiting the suspicious website, entered credentials into the scam form, or contacted infrastructure associated with the campaign.
Browser history and DNS logs can help reconstruct the sequence of events.
The timeline matters.
A visit to the scam page followed by installation of remote-access software is considerably more concerning than a blocked webpage that the user never interacted with.
Organizations Should Hunt for Remote-Access Abuse
The campaign highlights why remote-access tools deserve special attention in enterprise environments.
Many legitimate organizations use remote-management software every day. Blocking every remote-support tool may therefore be impractical.
Instead, defenders should monitor unusual combinations of behavior.
A remote-access application launched from an
Context is more valuable than simply maintaining a static list of software names.
Security Awareness Training Should Explain the Psychology
Traditional awareness training often tells users, “Do not click suspicious links.”
That advice is useful but insufficient.
Users should also understand how modern scareware works.
A website that suddenly announces that the computer is infected should trigger skepticism.
A webpage that tells someone to uninstall their antivirus should trigger immediate suspicion.
A stranger who asks for remote-access credentials should be treated as untrusted.
A refund process asking for cryptocurrency usernames and remote-access passwords should be considered a major fraud indicator.
These are behavioral rules that remain useful even when the scam’s domain, branding, and interface change.
Why Microsoft Branding Is So Effective
Microsoft is one of the most recognizable technology brands in the world.
Cybercriminals understand that many Windows users instinctively associate Microsoft’s name with operating-system security.
A fake Microsoft-themed page can therefore borrow credibility without actually having any relationship with Microsoft.
The same principle appears throughout technical support scams.
Attackers borrow the visual identity of trusted companies because victims often make decisions based on familiarity before verifying authenticity.
A Familiar Logo Does Not Establish Trust
Security teams should reinforce a simple principle:
Branding is not authentication.
A Microsoft-style logo, Windows-style interface, security shield, official-looking warning, or technical certificate graphic does not prove that the website belongs to Microsoft.
The browser address and the actual source of the software matter far more than visual presentation.
The Refund Story Is the Emotional Hook
The word “refund” is particularly effective because it creates a different emotional response from the usual malware warning.
Instead of telling victims they must pay to fix their computer, the scammers may tell them that money is already owed to them.
That can lower suspicion.
A victim who believes they are receiving money may become more willing to cooperate with a supposed support representative.
The scam therefore combines financial incentive with cybersecurity fear.
That combination can be extremely persuasive.
The Victim May Become the
One of the most disturbing aspects of this model is that the victim may voluntarily perform actions that benefit the attacker.
They may uninstall their antivirus.
They may install remote-access software.
They may disclose system information.
They may provide bank details.
They may reveal contact information.
They may share remote-access credentials.
The attacker does not necessarily need to break through the victim’s defenses.
The victim may be manipulated into opening the door.
What Windows Users Should Do
If a website suddenly claims that Windows security has failed, do not immediately follow its instructions.
Close the webpage.
Do not uninstall your antivirus because a random website instructed you to.
Do not call a phone number displayed in an unexpected security warning.
Do not install remote-access software at the request of an unsolicited “support” agent.
Do not provide passwords, remote-access IDs, banking information, or cryptocurrency account details.
Instead, open your operating
What To Do If You Already Interacted With the Scam
Anyone who has already submitted information should treat the incident seriously.
If remote-access credentials were shared, the remote-access software should be disconnected and investigated.
If passwords were entered, they should be changed from a trusted device, particularly where the same password was reused elsewhere.
If banking information was submitted, the financial institution should be contacted through an independently verified channel.
If cryptocurrency information was exposed, associated accounts should be reviewed for unauthorized activity.
And if remote access was granted, the affected computer should be treated as potentially compromised until properly investigated.
What Security Teams Should Learn From This Campaign
This campaign demonstrates that cybersecurity threats are increasingly combining several attack disciplines.
There is website impersonation.
There is browser fingerprinting.
There is scareware.
There is social engineering.
There is financial fraud.
There is credential harvesting.
There is remote-access abuse.
None of these components needs to be exceptionally sophisticated on its own.
The strength comes from combining them into a convincing sequence.
What Undercode Say: The Real Threat Is Manipulation
The most important lesson from this campaign is that cybersecurity is no longer only about detecting malicious files.
Attackers increasingly target human decision-making.
The fake scanner does not need kernel access.
It does not need to exploit Windows.
It does not need to defeat
It simply needs to convince someone that their computer is broken.
That is a powerful observation.
A technically sophisticated victim may still be vulnerable to a professionally designed psychological attack.
The fake scan demonstrates how easy it is to manufacture authority through interface design.
A progress bar creates the impression of activity.
A security score creates the impression of measurement.
Technical terminology creates the impression of expertise.
Real browser information creates the impression of personalization.
Microsoft branding creates the impression of legitimacy.
Together, these elements form a convincing illusion.
The random patch count is particularly revealing because it shows how little connection the “diagnosis” may have to the actual system.
The manipulated security score is even more important.
By forcing every result into a failing range, the website eliminates the possibility that the victim will receive reassuring information.
The scan is not designed to discover the truth.
It is designed to produce fear.
The antivirus-removal instruction then changes the situation from psychological manipulation into a potential security incident.
A user who was previously protected may voluntarily weaken their defenses.
That makes the next stage significantly easier.
The refund form reveals the financial objective behind the supposed security investigation.
The scammers are not simply trying to sell fake antivirus software.
They appear interested in personal information, financial details, remote-access credentials, and potentially direct control over the victim’s machine.
This makes the campaign more dangerous than a simple scareware popup.
The remote-access fields are arguably the biggest red flag in the entire operation.
A legitimate website does not need your remote desktop credentials to prove that your antivirus is working.
A legitimate refund department should not need unrestricted access to your computer simply because you visited a security scanner.
That mismatch between the claimed purpose and requested information should be treated as decisive evidence of fraud.
The campaign also demonstrates why threat intelligence should focus on infrastructure rather than individual domains.
If 11 sites are hosted together and follow the same technical pattern, discovering one domain may provide clues about the others.
Security researchers can potentially identify shared scripts, hosting relationships, DNS records, certificates, URL structures, and backend infrastructure.
This turns one scam page into an opportunity to uncover a larger network.
For defenders, browser telemetry becomes increasingly valuable.
A browser visit may look harmless at first, but the sequence of events afterward can reveal much more.
Did the user download an application?
Did a remote-access process launch?
Did the endpoint contact an unusual server?
Were credentials entered?
Did the user subsequently access financial services?
Security monitoring should connect these events.
The campaign also reinforces a broader cybersecurity principle: legitimate security software does not normally need to frighten you into trusting it.
Real security tools can report technical findings, but those findings should be reproducible and explainable.
When a random webpage insists that your entire computer is compromised and immediately instructs you to uninstall your protection, the correct response is not panic.
It is verification.
The industry should also pay closer attention to the accessibility of malicious social-engineering infrastructure.
A scammer does not need to create a sophisticated exploit when a carefully designed webpage can convince a user to perform the attacker’s preferred actions voluntarily.
That is why human-layer security deserves the same attention as endpoint and network security.
Ultimately, the fake Microsoft security scan is a reminder that the most dangerous part of a cyberattack may not be the code.
Sometimes it is the story.
The story says your computer is infected.
The story says Microsoft no longer supports your antivirus.
The story says you have a serious security problem.
The story says you are owed a refund.
And finally, the story says the only way to solve the problem is to trust the stranger on the other side of the phone.
Every part of that story is designed to move the victim closer to surrendering control.
That is the real attack.
✅ Third-Party Antivirus Support Claim Is False
Microsoft continues to support third-party antivirus products on Windows. The scam’s claim that Windows has stopped supporting third-party antivirus software is therefore misleading and should not be trusted.
✅ Browser Fingerprinting Claims Are Plausible
Web browsers can expose a variety of environmental information, including operating-system and hardware-related characteristics. However, access to that information does not mean a website has performed a full malware or kernel-security scan.
❌ The Fake Security Score Is Not Evidence
A security score artificially constrained to a low range cannot be treated as a genuine measurement of system security. Its purpose in this campaign is apparently to create urgency and persuade victims that their computers are dangerously compromised.
❌ A Website Cannot Magically Perform a Full Windows Security Audit
A normal webpage does not automatically have unrestricted access to kernel state, firmware configuration, antivirus internals, hardware security settings, or every installed Windows update. Claims to have inspected such areas should therefore be independently verified.
✅ Remote-Access Credentials Are a Serious Warning Sign
Requests for remote-access IDs, passwords, or similar credentials are highly suspicious in the context of an unsolicited security warning and refund offer. Sharing them can potentially give an attacker direct access to the victim’s system.
Prediction
(+1) Scam Detection Will Become More Automated
Browser security products, endpoint platforms, and threat-intelligence systems will increasingly identify fraudulent security-scanning infrastructure automatically.
(+1) Infrastructure-Based Hunting Will Expose Larger Scam Networks
Once researchers identify shared hosting, scripts, domains, and backend infrastructure, campaigns like this may be mapped far beyond their original landing pages.
(+1) Security Awareness Will Move Toward Social Engineering Defense
Organizations are likely to place greater emphasis on recognizing manipulative security warnings, fake technical-support calls, refund scams, and malicious remote-access requests.
(-1) AI-Generated Scam Pages Could Become Even More Convincing
Generative AI can lower the cost of producing professional-looking websites, realistic support scripts, localized content, and convincing technical explanations.
(-1) Remote-Access Fraud Will Remain a Major Risk
As long as legitimate remote-support applications remain widely used, scammers can continue hiding malicious behavior behind legitimate software.
(-1) Technical Language Will Continue To Be Weaponized
Terms such as TPM, Rowhammer, WebRTC, kernel protection, sandboxing, and vulnerability scores can be repurposed as psychological weapons even when the underlying diagnosis is completely fabricated.
The Bottom Line
This campaign is not frightening because the fake scanner is technically sophisticated.
It is frightening because it does not need to be.
A convincing interface, a few real browser details, several fabricated warnings, a low security score, and a carefully designed refund story can turn an ordinary Windows user into a willing participant in the attack.
The safest response to an unexpected security warning is simple: stop, close the page, and verify the claim through a trusted security tool or official source.
If a website tells you to uninstall your antivirus, provide remote-access credentials, or hand over financial information, the warning is no longer something you should investigate from inside that webpage.
It is something you should walk away from.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




