Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
This message directs the target user to a malicious landing page through an embedded link. Initially, the web page looks completely harmless or shows a blank screen. However, a hidden trigger within the code executes under specific environmental conditions.
To begin with, the attack sequence usually starts with a deceptive phishing email. This message directs the target user to a malicious landing page through an embedded link.
When users attempt to regain control or call the number, they are met by scammers posing as Microsoft support.
Following this, once validation succeeds, the system launches the CypherLoc scareware kit into full execution mode. The original webpage erases itself instantly to display a highly counterfeit security alert interface.
After successful decryption, the original page erases itself and places an entirely new page in the browser.
The code only decrypts when the page is opened under the right conditions: when the required URL fragment hash is present and the page passes a series of cryptographic integrity checks. Alternatively, if an automated web scanner opens the link without the correct token, the exploit script refuses to activate.
The code only decrypts when the page is opened under the right conditions: when the required URL fragment hash is present and the page passes a series of cryptographic integrity checks. Alternatively, if an automated web scanner opens the link without the correct token, the exploit script refuses to activate.
If an experienced user attempts to open browser developer tools to investigate, the platform launches defensive countermeasures. Specifically, the code triggers a continuous loop of asset reloads and layout recalculations to crash the analysis environment. This excessive noise causes intense browser instability.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser-based scareware kit used in technical support scam campaigns. It decrypts and activates only under specific conditions, replaces the page with fake security alerts, forces fullscreen behavior, disables browser controls, hides the cursor, plays repetitive warning audio, displays the victim's public IP address, and interferes with developer tools to hinder analysis and pressure victims into calling fraudulent support lines.
CypherLoc is a scareware campaign that uses phishing emails to lure victims to malicious webpages, then manipulates the browser into full-screen mode, disables normal controls, displays fake security alerts, and presents a fraudulent support number so scammers can steal sensitive information such as banking details and passwords.
CypherLoc is a browser-based scareware scheme that uses an encrypted JavaScript loader to validate, decrypt, and execute a hidden payload, replace the runtime page, lock the browser in full-screen mode, play warning audio, display the victim’s public IP address for intimidation, and present fake login forms purely as psychological pressure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.