Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials

A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.

A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.

Users receive an email featuring Microsoft's logo, claiming an urgent financial or security issue. Recipients are prompted to click a link to verify their identity or resolve the issue.

According to Cofense analysts, threat actors employ social engineering tactics, combining payment lures with deceptive user interface overlays to enhance their methods.

Clicking the link redirects users to a fake CAPTCHA challenge, simulating a trusted verification process.

Upon completing the verification, users encounter a locked browser window with multiple pop-ups mimicking genuine Microsoft security alerts.

The scam intends to create panic, leading users to believe their system is compromised. Victims are often directed to a fake support phone number masquerading as Microsoft's helpline.

A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.
Brooke Sanders · Thehackingpost

Calling the number connects users to a malicious actor posing as a support technician. The scammer then persuades victims to provide Microsoft account credentials or install remote desktop software, granting full access to the attacker's infrastructure.

The infection begins with URLs serving as redirectors and payload hosts. Initial redirector domains include:

hxxps://alphadogprinting.com/index.php?8jl9lz hxxps://amormc.com/index.php?ndv5f1

These URLs lead victims through a CAPTCHA page before reaching the malicious overlay server. Payload domains, such as:

Advertisement

hxxps://my.toruftuiov.com/9397b37a-50c4-48c0-899d-f5e87a24088d hxxps://deprivy.stified.sbs/proc.php

host scripted overlays that manipulate the DOM, disable mouse control, and display fake alerts.

The browser lock is illusory and can be dismissed by pressing the ESC key, although few victims realize this before contacting the attacker.

This campaign exemplifies an evolving threat, blending trusted logos with multiple redirect stages and UI deception to facilitate credential theft .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories