Researchers uncovered a refund scam campaign using Microsoft-branded "SysScan" websites that pretend to test whether a victim’s antivirus is working, then display fabricated security findings to claim third-party protection is causing serious problems or is no longer supported by Windows. The pages do not perform real diagnostics; instead, they rely on basic browser-visible system details plus hardcoded or randomized results to ensure alarming outcomes and pressure users to uninstall their antivirus software.
After the fake scan, the sites collect extensive personal, banking, antivirus, and remote-access information through forms apparently built to support live scam operators during follow-up calls, including fields for agent identifiers and selected security products. Researchers identified 11 such sites on a single host and found that submitted data is sent directly to Telegram via the bot API, after which victims are placed on a waiting page promising a callback from a refund manager; parts of the site code and media also showed signs of being AI-generated or adapted from a broader scam template.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers determined the browser-based scans cannot perform real endpoint security checks and instead combine limited browser-exposed data with hardcoded or randomized findings to guarantee alarming results. They also noted heavily commented code and labels marking checks as fake or exaggerated, suggesting parts of the scam code may have been AI-generated or AI-assisted.
Analysis showed the scam sites collect personal, banking, antivirus, and remote-access details through an operator-oriented form and send submitted data directly to Telegram’s bot API without requiring a backend server. The sites then redirect victims to a waiting page promising a callback from a refund manager within three to five minutes.
Researchers identified a refund scam campaign using Microsoft-branded fake “SysScan” websites that simulate security scans, pressure victims to uninstall antivirus software, and funnel them into a phone-based fraud workflow. They found eleven related sites on a single host and linked the campaign to IP 157.230.180.90 and multiple SysScan-themed domains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.