Skip to content
DnsLister Forum

Where domain hunters compare notes

Fake Microsoft security scans trick victims into uninstalling their antivirus

This is a classic social engineering attack chain that weaponizes user trust in Microsoft branding to disable defenses before the real payload hits.

The Hook: Threat actors are deploying fake, Microsoft-branded security scanners that don't just scare users with fake detections—they actively instruct victims to uninstall their legitimate antivirus software. Once the AV is gone, the scam pivots into a refund fraud scheme, likely leading to remote access tool (RAT) deployment or credential theft.

Technical Breakdown: – Initial Access (T1566): Likely delivered via malvertising, tech support scam pop-ups, or phishing emails mimicking Microsoft Defender alerts. – Defense Evasion (T1562.001): The core TTP. The fake scanner explicitly tells the user to disable or uninstall their real AV, claiming it's "conflicting" with the Microsoft scan. – User Execution (T1204): Victim runs the fake scanner executable. – Monetization: Refund scam. The attacker likely requests remote access (e.g., via ConnectWise, AnyDesk) to "process the refund," then siphons banking credentials or deploys ransomware. – IOCs: Not provided in the summary, but typical indicators would include domains mimicking microsoft-<random>.com, executables named SecurityScanner.exe or DefenderFixTool.exe, and phone numbers embedded in the popup UI.

Defense: – User Education: Train users that Microsoft will never cold-call or display a popup asking them to uninstall their AV. – AppLocker / WDAC: Block execution from %TEMP% and %APPDATA% for non-admin users. – EDR Alerting: Monitor for processes spawning msiexec.exe or rundll32.exe from browser download directories, and alert on any script that attempts to disable security services.

Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *