← Back
PhishingMalwarebytes Labs·4 hours ago

Fake Microsoft security scans trick victims into uninstalling their antivirus

Attackers are deploying counterfeit Microsoft security scanners that fabricate threats and convince users to disable their legitimate antivirus software, leaving systems vulnerable to further compromise. Once victims uninstall their protections, the scammers redirect them into refund fraud schemes, exploiting the deception to extract payment.

Read full article at Malwarebytes Labs

Related Articles

PhishingInfosecurity Magazine·6 hours ago

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

Threat actor Doubloon Dredger is leveraging Notion, a legitimate productivity platform, alongside malicious PDFs to conduct authentication token harvesting attacks targeting Microsoft credentials. This technique exploits user trust in commonly-used services to compromise account access and enable lateral movement within targeted organizations.

PhishingHelp Net Security·14 hours ago

Fake bank websites play dead to evade security scanners

Fortra's threat intelligence team has identified a phishing technique called Chameleon SEO Poisoning that leverages manipulated search results and cloaked fake banking websites to harvest credentials while remaining invisible to security scanners. The attackers optimize these pages for high-intent keywords mimicking legitimate banking portals and reported a 40% increase in cases during Q2 2026. The websites employ evasion tactics to detect and avoid security tools, making this approach particularly difficult for traditional detection methods.

PhishingSecurityWeek·3 days ago

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

Researchers have identified iAuthFlow V2, a phishing toolkit that exploits passkey authentication by registering attacker-controlled passkeys to maintain persistent access to compromised accounts. This capability allows attackers to retain access even after victims reset their passwords or revoke active sessions, representing a significant evolution in phishing attack sophistication that targets modern authentication mechanisms.

PhishingHelp Net Security·3 days ago

A $25 template helped scammers build hundreds of phantom bank domains

Researchers at Allure Security discovered a widespread scam operation leveraging a cheap website template to create hundreds of fraudulent bank domains designed to deceive victims. The investigation began when a suspicious domain mimicking a legitimate financial services client was found hosting an unrelated bank's branding, ultimately revealing a coordinated scheme to build phantom banking sites for scamming purposes. The $25 template appears to have been a key tool enabling scammers to rapidly deploy deceptive financial websites at scale.

Fake Microsoft security scans trick victims into uninstalling their antivirus | Threat Hunters Journal