Multiple brand-impersonation scams are targeting consumers by pushing them to interact with fake customer support and surrender sensitive data. One campaign uses a fraudulent site styled as Avast to convince French-speaking users they were charged €499.99 and must act quickly to “cancel” and receive a refund; the page dynamically inserts the current date via JavaScript, loads the Avast logo from Avast’s own CDN to appear legitimate, and then harvests full payment-card details (PAN, expiry, and CVV) via a cancellation/refund form.
Separate but related social-engineering activity targets Robinhood users with “security alert” SMS and email lures that direct victims to call scam call-center numbers, where operators attempt to extract login credentials, 2FA codes, and other personal/financial information; the email variant also commonly pushes victims toward installing remote-access tools such as AnyDesk or TeamViewer under the guise of support. In another consumer fraud pattern, scammers posing as a mobile carrier (e.g., Spectrum) call shortly after a phone delivery, claim the wrong device was shipped, and trick the recipient into mailing the phone to the attacker—enabling resale and potential identity-fraud follow-on if the device/line is activated under the victim’s details.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A billing-themed email scam impersonated a subscription renewal for 'Premium Multi-Device Protection,' claimed a $238.88 charge, and urged recipients to call +1 (813) 543-3317 for cancellation or support. The apparent goal was to socially engineer victims into disclosing personal and financial information over the phone.
A social-engineering scam targeted people who had just received new phones, with callers impersonating carriers and claiming the wrong device had been shipped so it needed to be returned. The fraud used urgency, knowledge of order details, and sometimes QR-code shipping workflows to facilitate theft of the device.
A related Robinhood scam campaign used SMS messages such as fake withdrawal-code alerts and phone-number-change notices to get recipients to call attacker-controlled support numbers. The call-center-style operation then socially engineered victims into disclosing account, personal, and financial information.
A phishing campaign impersonating Avast used a fake €499.99 charge and refund/cancellation pretext to trick French-speaking users into submitting personal and payment card details. The scam site mimicked Avast branding, validated card numbers, and sent captured data to a backend endpoint while using live chat to pressure victims.
A scam campaign impersonating Robinhood sent fake security-alert emails claiming a login from a new device and urging recipients to call fraudulent customer-support numbers. The operators attempted to steal credentials, 2FA codes, wallet recovery phrases, or persuade victims to transfer funds and install remote-access tools.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourcemalwarebytes.com
Open sourceonlinethreatalerts.com
Open sourcezdnet.com
Open sourceonlinethreatalerts.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.