Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
August 25, 2026
AI Security Startup Alice Raises $140M Amid Surging Enterprise AI Threats
August 25, 2026
SynkLoader Malware Impersonates IT Support on Microsoft Teams
August 25, 2026
Home/Threats/Fake Microsoft Security Scan Tricks Users into Removing Antivirus
Threats

Fake Microsoft Security Scan Tricks Users into Removing Antivirus

Key Takeaways A new web-based scam leverages fake Microsoft-branded security scans to deceive users. Victims are manipulated into uninstalling legitimate antivirus software under false pretenses. The...

Marcus Rodriguez
Marcus Rodriguez
August 25, 2026 4 Min Read
4 0

Key Takeaways

  • A new web-based scam leverages fake Microsoft-branded security scans to deceive users.
  • Victims are manipulated into uninstalling legitimate antivirus software under false pretenses.
  • The scam employs tailored, but fabricated, scan reports and pushes for a fraudulent refund process.
  • The ultimate goal is to gain remote access to victims’ computers and extract sensitive financial information.
  • Eleven related scam sites, all using similar SysScan branding, have been identified.

Sophisticated Web Scam Targets Antivirus Software

A deceptive new online scheme is actively tricking users into removing their crucial antivirus protection by presenting fabricated Microsoft security alerts. These fraudulent web pages simulate a device scan, then falsely report severe security vulnerabilities and claim that third-party antivirus products are incompatible with Windows systems. This assertion is entirely untrue, yet the messaging is crafted to evoke urgency and a sense of personalized threat.

Table Of Content

  • Key Takeaways
  • Sophisticated Web Scam Targets Antivirus Software
  • The Anatomy of Deception: Fake Scans and False Claims
  • The “Refund” Trap: Remote Access and Financial Fraud
  • What You Should Do
  • Indicators of Compromise (IoCs)

The scam websites gather basic browser information, such as screen resolution and device specifics, to generate a seemingly customized scan report. This personalization enhances the illusion of legitimacy, but the true objective is to steer victims toward a bogus refund process. According to a Malwarebytes report, researchers have identified eleven interconnected sites operating from the same server, all participating in this coordinated attack.

The Anatomy of Deception: Fake Scans and False Claims

Each of these malicious sites employs similar “SysScan” branding and falsely portrays itself as an official Microsoft security check. They systematically inform visitors that their installed antivirus software is the root cause of alleged system issues. The attack does not rely on a direct file download; instead, it uses a meticulously designed website, a misleading security score, a data collection form, and the promise of a follow-up phone call to progressively build trust. By the time scammers request remote access or banking details, victims may already be convinced they are engaged in a legitimate support or refund procedure.

The scam pages display warnings that browsers are incapable of verifying. They falsely claim to detect problems related to browser isolation, memory integrity, firmware security settings, Windows updates, and processor performance. Crucially, a standard website cannot access these deep system components or accurately assess the functionality of a user’s antivirus protection.

To bolster credibility, the scam incorporates genuine, publicly available browser details such as the operating system, CPU core count, screen dimensions, and certain enabled features or permissions. However, these legitimate data points are then interwoven with pre-set, alarming warnings to construct a report that appears both technical and dire.

Researchers discovered that many of the “scan findings” are hard-coded into the web pages, rather than being the result of an actual system analysis. The fabricated security score is consistently low, ranging from 13 to 30 out of 100, ensuring no visitor receives a positive outcome. This fear-mongering tactic mirrors other fake antivirus website campaigns. The most dangerous instruction is the demand for users to uninstall their legitimate antivirus software. While Windows can indeed set Microsoft Defender Antivirus to a passive mode when another compatible security product is installed, this does not imply that Windows has ceased support for third-party solutions. Recent reports on tools capable of disabling Windows Defender protection underscore why attackers prioritize neutralizing endpoint defenses.

The “Refund” Trap: Remote Access and Financial Fraud

Following the deceptive scan, the sites present a form requesting a wide array of personal and financial information. This includes names, home addresses, phone numbers, email addresses, bank details, purported refund amounts, cryptocurrency usernames, antivirus product specifics, and even remote-access session credentials. The form also features fields for an “agent ID,” “agent name,” and “company,” suggesting that a scam operator might guide the victim through the process during a phone call. Victims are then offered a choice of 30 remote-access tools, providing criminals a pathway to seize control of the computer once they have convinced the user that a refund is pending.

Upon submission, the collected data is bundled and transmitted to Telegram via its bot API, as detailed by Malwarebytes. The victim is then redirected to a page promising a call from a “refund manager” within three to five minutes, accompanied by a looping office video designed to lend an air of authenticity to the wait. This handoff is critical, as remote-access software grants criminals a direct view of sensitive accounts and files. Similar refund scams have previously exploited legitimate remote monitoring tools to manipulate banking activities or maintain persistent control over a victim’s device, echoing the patterns observed in remote monitoring software abuse.

What You Should Do

  • Be highly suspicious of any web page claiming to perform a comprehensive computer security scan. Legitimate companies will never demand the removal of protective software as a condition for support, a refund, or a security check.
  • If a web scan produces only negative results and demands immediate action, close the page immediately.
  • If you have already granted remote access to your device, disconnect it from the internet, remove any remote-access tools, reinstall and update your antivirus software, and perform a full system scan.
  • If banking information was shared or online banking was accessed during the scam call, contact your bank immediately using a phone number obtained independently (e.g., from their official website or the back of your card).
  • Change all email and banking passwords from a separate, trusted device.
  • Do not let embarrassment prevent you from reporting such incidents. Prompt action can significantly mitigate potential financial losses or further account compromises.

Indicators of Compromise (IoCs)

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft August 2023 Update Breaks PDF/XPS Generation

Next Post

ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
WhatsApp Adds Passkey Support for 1 Billion Users, Bolstering Two-Step Verification
August 25, 2026
ToxNetV2 Linux Botnet Leverages NVIDIA AI to Automate Attacks
August 25, 2026
Fake Microsoft Security Scan Tricks Users into Removing Antivirus
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us
Type Indicator Description
IP address 157.230.180.90 Hosting server associated with the scam sites
Domain detectsysscanner[.]at Scam site domain
Domain detectsysscanner[.]com Scam site domain
Domain detectsysscanner[.]de Scam site domain
Domain detectsysscanner[.]in[.]net Scam site domain
Domain detectsysscanner[.]xn--q9jyb4c