SysScan Refund Scam Mimics Microsoft Security Tools
Score: 7/10

SysScan Refund Scam Mimics Microsoft Security Tools

The SysScan refund scam uses fraudulent Microsoft-branded security scans to deceive users into uninstalling antivirus software and providing remote access credentials.

Executive Summary

A campaign known as SysScan utilizes fake Microsoft-branded websites to trick users into believing their systems are compromised or that their third-party antivirus software is no longer supported by Windows. The scam centers on a browser-based diagnostic tool that provides hard-coded or exaggerated negative results to instill fear. The ultimate goal is to facilitate a 'refund scam' where victims are induced to provide sensitive banking information and remote access credentials.

Technically, the scam employs sophisticated social engineering by reading legitimate browser data (User Agent, screen size, processor count) to appear authentic. Once a victim is convinced, they are prompted to uninstall their security software and fill out a comprehensive data collection form. This data, which includes bank details and remote access passwords for 30 different tools, is exfiltrated directly to attackers via the Telegram Bot API.

This campaign represents a significant risk to home users and corporate employees alike, as it targets enterprise security software and leverages AI-generated code and media to enhance credibility. The removal of security tools leaves systems vulnerable to secondary infections and direct financial theft.

Key Details

Threat Name

SysScan Refund Scam

Affects

—

Adversary

—

MITRE Techniques

Malware/Tools

SysScan

Report Score

7out of 10
Quality Score
Good
IOC Quality9
TTP Details8
Detection Guidance3
Enterprise Relevance6
Clarity & Structure8
Technical Depth7

Sources