New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials
A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.
A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.
Users receive an email featuring Microsoft's logo, claiming an urgent financial or security issue. Recipients are prompted to click a link to verify their identity or resolve the issue.
According to Cofense analysts, threat actors employ social engineering tactics, combining payment lures with deceptive user interface overlays to enhance their methods.
Clicking the link redirects users to a fake CAPTCHA challenge, simulating a trusted verification process.
Upon completing the verification, users encounter a locked browser window with multiple pop-ups mimicking genuine Microsoft security alerts.
The scam intends to create panic, leading users to believe their system is compromised. Victims are often directed to a fake support phone number masquerading as Microsoft's helpline.
A new phishing campaign exploits Microsoft's branding to deceive users into a tech support scam.
Calling the number connects users to a malicious actor posing as a support technician. The scammer then persuades victims to provide Microsoft account credentials or install remote desktop software, granting full access to the attacker's infrastructure.
The infection begins with URLs serving as redirectors and payload hosts. Initial redirector domains include:
hxxps://alphadogprinting.com/index.php?8jl9lz hxxps://amormc.com/index.php?ndv5f1
These URLs lead victims through a CAPTCHA page before reaching the malicious overlay server. Payload domains, such as:
hxxps://my.toruftuiov.com/9397b37a-50c4-48c0-899d-f5e87a24088d hxxps://deprivy.stified.sbs/proc.php
host scripted overlays that manipulate the DOM, disable mouse control, and display fake alerts.
The browser lock is illusory and can be dismissed by pressing the ESC key, although few victims realize this before contacting the attacker.
This campaign exemplifies an evolving threat, blending trusted logos with multiple redirect stages and UI deception to facilitate credential theft .
Based on reporting by Cyber Security News.
