Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
7-Zip Flaws Allow Arbitrary Code Execution, Vulnerabilities Attackers
May 26, 2026
Anthropic’s Restricted Claude Nears Public Release via Code
May 26, 2026
Cloud Atlas APT Modifies termsrv.dll for Group Enable
May 25, 2026
Home/Threats/Hackers Use CypherLoc Kit for Fake Microsoft Browser-Locking Push
Threats

Hackers Use CypherLoc Kit for Fake Microsoft Browser-Locking Push

A newly identified scareware kit, dubbed CypherLoc, is actively locking victims’ web browsers and coercing them into calling fake Microsoft support lines. This browser-locking push, which aims to...

Jennifer sherman
Jennifer sherman
May 25, 2026 4 Min Read
9 0

A newly identified scareware kit, dubbed CypherLoc, is actively locking victims’ web browsers and coercing them into calling fake Microsoft support lines. This browser-locking push, which aims to trick users into contacting fraudulent “Microsoft support” for technical assistance scams, is detailed in a recent security analysis. The comprehensive report on CypherLoc’s operations and tactics can be

The kit has been linked to roughly 2.8 million attacks since the start of 2026, making it one of the more aggressive browser-based threats observed this year.

Unlike traditional malware that requires a file to be downloaded and installed, CypherLoc runs entirely inside the web browser. It begins with a phishing email that nudges the victim toward a malicious web page through an embedded link or an attachment.

Once the page opens, it appears completely harmless at first. Over time, it quietly transforms into a full-screen scareware environment designed to terrify the user and keep them trapped on the page.

Barracuda Research, the threat intelligence arm of Barracuda, said in a report shared with Cyber Security News that the kit combines advanced evasion techniques, aggressive browser controls, and psychological manipulation to push victims into calling fraudulent technical support phone numbers.

Researchers at the firm have been tracking this kit closely since attacks began spiking earlier this year. What makes CypherLoc stand out is how well it hides from security scanners.

CypherLoc Execution Flow (Source - Barracuda)
CypherLoc Execution Flow (Source – Barracuda)

Its payload is encrypted and buried inside the web page code, and it will only activate if very specific conditions are met. If those conditions are missing, the page quietly redirects to a blank screen, hiding the threat from automated analysis tools and sandboxes.

The kit also fights back when someone tries to investigate it. Opening the browser’s developer tools triggers a flood of activity, including asset reloads and repeated layout recalculations, that overwhelms analysis tools and pushes the browser toward instability and system error dialogs.

Browser-Locking CypherLoc Kit

Once CypherLoc decrypts and activates, it takes full control of the browser. It switches to full-screen mode, disables right-click menus, hides the cursor, and covers the entire screen with overlays.

Every time the user tries to regain control, the page immediately relocks, creating a strong sense of entrapment. The kit adds audio pressure on top of the visual chaos. Warning sounds play automatically whenever the user clicks anywhere or the page reloads.

This extra noise makes the browser feel unstable, deepening the illusion that something is seriously wrong with the device.

Encrypted JavaScript Loader (Source - Barracuda)
Encrypted JavaScript Loader (Source – Barracuda)

To make things feel personal, CypherLoc retrieves and displays the victim’s real public IP address on the landing page, a psychological tactic designed to make the warning feel targeted and urgent.

Fake login forms also appear, asking victims to enter usernames and passwords. These forms never process any input.

Their purpose is psychological: they make the threat look legitimate, keep the victim on the page longer, and escalate panic when entering credentials fails.

A fraudulent phone number, presented as the only fix, stays prominently on screen throughout. When victims call, operators posing as Microsoft support staff continue the scam through a live conversation.

How CypherLoc Evades Detection

The technical engine behind CypherLoc is what sets it apart from older, cruder scareware. The payload is encrypted using AES and only unlocks when a specific value is present in the URL fragment.

The page also runs a series of cryptographic integrity checks before executing anything. If any check fails, the payload refuses to run and the user sees nothing suspicious.

Spoofed Login Form (Source - Barracuda)
Spoofed Login Form (Source – Barracuda)

After a successful decryption, the original page erases itself and replaces its content with a brand-new scareware page inside the browser. This sudden swap resets any live inspection scripts and makes the page feel dangerous rather than deliberately crafted.

Security teams should maintain robust anti-phishing, browser, and endpoint protections capable of detecting suspicious script behavior. User education is equally important, since legitimate security alerts never lock browsers, display phone numbers, or demand immediate action through pop-ups.

As attackers move away from traditional malware and toward browser-based manipulation, organizations need defenses focused on protecting people, not just devices. CypherLoc is a sharp reminder that fear itself can be a cybercriminal’s most effective tool.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Pentest Agent Suite: Bug Bounty Framework for AI Claude Code

Next Post

CISA Warns: Drupal Core SQL Injection Vulnerability Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Hide Linux Payload During Package Install via
May 25, 2026
Russian Hacker Uses Jailbroken Gemini to Steal Credentials & Drain
May 25, 2026
Hackers Exploit CDN to Bypass Domain Reputation Abuse Shared
May 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us