Threats Tagged 'tech support scam'
View all threats tagged with 'tech support scam'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tech support scam'
Click on any threat for detailed analysis and mitigation recommendations
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e... Join the discussion | AlienVault OTX General | 09/06/2026, 07:32:55 UTC Added: 09/07/2026, 10:22:27 UTC |
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves. Join the discussion | AlienVault OTX General | 08/14/2026, 07:26:08 UTC Added: 08/14/2026, 10:56:30 UTC |
A new tech support scam campaign exploits Microsoft's trusted brand to deceive users. It starts with phishing emails promising payments, leading victims to fake CAPTCHA challenges. After completion, users are redirected to a browser-locked landing page mimicking ransomware, with multiple pop-ups resembling Microsoft security alerts. These pop-ups urge victims to call a fraudulent support number, enabling phone-based social engineering. The scam combines browser manipulation, phishing, and social engineering to potentially gain system access. No direct malware or exploits are involved, but the psychological manipulation can lead to financial loss or unauthorized access. The campaign underscores the risks of trusting familiar branding without verification and highlights the need for user awareness and layered defenses. Indicators include multiple malicious URLs and domains used in the campaign. The threat is medium severity due to its social engineering nature and potential impact on confidentiality and integrity. Join the discussion | AlienVault OTX General | 10/21/2025, 16:01:23 UTC Added: 10/21/2025, 16:05:24 UTC |
Showing 1 to 3 of 3 results