Mouse movement triggers fake security alert in tech support scam | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


What would you do if, after clicking an ad on a legitimate website, a full-screen security alert appeared and told you to call tech support? That is the scenario created by a scam campaign analysed by Netskope Threat Labs.

The chain begins with ads, mainly delivered through Google Ads, appearing on popular legitimate websites, including mapping, weather, sports and property sites. According to Netskope, the presence of the ads does not mean those sites have been compromised: they are delivered through ordinary advertising inventory. After clicking an ad, the user sees a loading screen and is then taken to ShopEase, a fake online store that appears harmless.

The fake alert appears when the user moves the mouse

The store acts as a commercial front until the user moves the mouse. By waiting for that interaction before displaying the fake alert, the campaign attempts to evade automated crawlers that inspect the page without generating a mouse movement, Netskope explains.

“Only once that movement is detected does the kit decrypt a hidden C2 address, pull down an encrypted payload (tailored to whether the victim is on Windows or a Mac), and assemble the fake alert within browser memory, so no inspectable file crosses the network,” Netskope details in its report.

An apparent lockout designed to prompt a call

To make the problem appear serious, the page switches to full-screen mode, hides the address bar, tabs and cursor, and attempts to prevent users from using familiar keys and shortcuts to leave. It also plays alarm sounds, slows down the browser and displays flashing messages warning users not to restart their computers and urging them to call the number on screen immediately.

Everything happens within the browser: the campaign does not encrypt files or take control of the operating system. Its aim is to convince the victim that urgent help is needed. During the call, the scammers may try to charge for a nonexistent service, obtain login credentials or financial information, or persuade the victim to install a remote access tool.

Campaign reach and advice for users

Netskope Threat Labs tracked the campaign for two weeks. During that period, it identified at least 619 organisations affected, 457 hosts associated with the scam infrastructure, more than 250 campaign identifiers and activity on 284 legitimate websites. The United States accounted for nearly 62% of the organisations identified, followed by Japan at 16% and Australia at 14%.

Netskope advises anyone who encounters such an alert not to call the displayed number, provide information or install software. To close it, users can hold down the Escape key for a few seconds or force the browser to quit using Windows Task Manager or the Force Quit option on macOS. When reopening the browser, they should avoid automatically restoring the previous session.

The company also notes that a legitimate operating system or browser alert will never require users to call a number displayed in a pop-up.

What would you do if, after clicking an ad on a legitimate website, a full-screen security alert appeared and told you to call tech support? That is the scenario created by a scam campaign analysed by Netskope Threat Labs.

The chain begins with ads, mainly delivered through Google Ads, appearing on popular legitimate websites, including mapping, weather, sports and property sites. According to Netskope, the presence of the ads does not mean those sites have been compromised: they are delivered through ordinary advertising inventory. After clicking an ad, the user sees a loading screen and is then taken to ShopEase, a fake online store that appears harmless.

The fake alert appears when the user moves the mouse

The store acts as a commercial front until the user moves the mouse. By waiting for that interaction before displaying the fake alert, the campaign attempts to evade automated crawlers that inspect the page without generating a mouse movement, Netskope explains.

“Only once that movement is detected does the kit decrypt a hidden C2 address, pull down an encrypted payload (tailored to whether the victim is on Windows or a Mac), and assemble the fake alert within browser memory, so no inspectable file crosses the network,” Netskope details in its report.

An apparent lockout designed to prompt a call

To make the problem appear serious, the page switches to full-screen mode, hides the address bar, tabs and cursor, and attempts to prevent users from using familiar keys and shortcuts to leave. It also plays alarm sounds, slows down the browser and displays flashing messages warning users not to restart their computers and urging them to call the number on screen immediately.

Everything happens within the browser: the campaign does not encrypt files or take control of the operating system. Its aim is to convince the victim that urgent help is needed. During the call, the scammers may try to charge for a nonexistent service, obtain login credentials or financial information, or persuade the victim to install a remote access tool.

Campaign reach and advice for users

Netskope Threat Labs tracked the campaign for two weeks. During that period, it identified at least 619 organisations affected, 457 hosts associated with the scam infrastructure, more than 250 campaign identifiers and activity on 284 legitimate websites. The United States accounted for nearly 62% of the organisations identified, followed by Japan at 16% and Australia at 14%.

Netskope advises anyone who encounters such an alert not to call the displayed number, provide information or install software. To close it, users can hold down the Escape key for a few seconds or force the browser to quit using Windows Task Manager or the Force Quit option on macOS. When reopening the browser, they should avoid automatically restoring the previous session.

The company also notes that a legitimate operating system or browser alert will never require users to call a number displayed in a pop-up.


——————————————————-


Click Here For The Original Source.