A large-scale scareware and phishing campaign dubbed CypherLoc has targeted about 2.8 million people by steering users to malicious webpages that simulate severe security incidents and pressure them into calling fraudulent support lines. Researchers said the pages abuse browser features to enter full-screen mode, hide the cursor, disable context menus, and display fake alerts, while also showing the victim’s public IP address and counterfeit login prompts to make the warnings appear legitimate. Victims who call are connected to scammers posing as Microsoft support, who attempt to steal passwords, banking details, and other sensitive information.
The operation relies on social engineering rather than software exploitation, combining phishing emails with browser-locking tactics to create urgency and panic. Reporting indicates the campaign has spread widely since early 2026, with defenders urged to reinforce user awareness around unsolicited emails, links, and attachments and to treat unexpected security warnings and support phone numbers as suspicious, especially when presented through intrusive browser behavior.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A large-scale scareware and phishing campaign dubbed CypherLoc was reported as having spread widely since early 2026, targeting about 2.8 million people through phishing emails and browser-locking social engineering rather than software exploits. Victims were lured to malicious pages showing fake security alerts, public IP information, and fraudulent Microsoft support numbers to steal passwords and banking details.
TechRadar summarized CYFIRMA's findings, describing Operation SilentCanvas as a professionally engineered campaign targeting enterprises and organizations that use remote administration tools. The coverage highlighted its use of trojanized ScreenConnect, credential theft, screen and microphone capture, clipboard monitoring, and recommendations for detection and containment.
CYFIRMA reported a multi-stage intrusion campaign using a weaponized JPEG file named sysupdate.jpeg to launch obfuscated PowerShell, deploy a trojanized ConnectWise ScreenConnect instance, and establish persistence via a fake OneDriveServers Windows service. The report detailed AMSI bypass, UAC bypass, encrypted command-and-control, and capabilities including credential theft, surveillance, and potential ransomware enablement.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetechradar.com
Open sourcecyfirma.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.