A group of Microsoft-branded SysScan websites is using fake security scans to falsely claim that third-party antivirus on Windows is causing serious problems and should be uninstalled. The scam funnels victims into a refund call, collects personal and banking details, and sends the data to Telegram while presenting a fake handoff to a ārefund manager.ā #SysScan #Microsoft #Telegram #MicrosoftDefenderAntivirus
Keypoints
- The investigation found 11 related scam sites on a single host, all using similar Microsoft branding and fake scan results.
- The pages falsely claim Windows no longer supports third-party antivirus and pressure users to uninstall it immediately.
- The scan is not real; it only reads browser-exposed data and combines it with invented conclusions and fixed fake checks.
- The scam collects extensive victim data, including name, address, phone numbers, email, refund details, banking information, and remote-access credentials.
- Submitted form data is sent directly to Telegramās bot API, with no traditional backend used, making the operation cheap and disposable.
- The sites then redirect victims to a waiting page that promises a refund manager call within minutes, reinforcing the illusion of legitimacy.
- Indicators in the code suggest the pages may have been built with AI-assisted coding and adapted from a broader scanner template.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link ā Victims are lured to a fake Microsoft-branded scan site that initiates the refund scam and harvests information by presenting a convincing but fraudulent security check (āA website claims to find deep problems with your computerā¦ā).
- [T1204.001 ] User Execution: Malicious Link ā The scam depends on the user visiting the website, running the fake scan, and proceeding through the form and refund steps (āRun the scan againā, āAfter submitting the formā).
- [T1041 ] Exfiltration Over C2 Channel ā Submitted customer and banking data is bundled and sent directly to Telegramās bot API for collection by the scammers (āthe browser bundles⦠into a single message and sends it directly to Telegramās bot APIā).
- [T1001 ] Data Obfuscation ā The site mixes real browser data with fabricated checks and random results to make the output seem credible while hiding the true nature of the scam (āreads information⦠but the security conclusions arenāt connectedā).
- [T1056.001 ] Input Capture: Keylogging ā The form is designed to capture sensitive information entered by the victim or operator, including banking and remote-access credentials (āIt collects a name, address⦠and the ID and password for a remote-access sessionā).
- [T1219 ] Remote Access Software ā The scam explicitly requests installation/use of remote-access tools and collects credentials for them as part of the fraud (āUsers can choose from 30 different remote-access toolsā, āinstall remote-access softwareā).
- [T1055 ] Process Injection ā Not mentioned.
Indicators of Compromise
- [IP address ] Single hosting IP used for the scam site cluster ā 157.230.180.90
- [Domains ] Microsoft-branded fake scan and related lookalike domains ā detectsysscanner[.]at, detectsysscanner[.]com, techsysscanner[.]com, and 7 more domains
- [Platform/API ] Data collection endpoint used to exfiltrate form submissions ā Telegramās bot API
- [Branding/Service names ] Fake scanner branding and misleading product references ā SysScan, Microsoft Defender Antivirus