New Tech Support Scam Exploits Microsoft Logo to Steal User Credentials
Recent analyses by the Cofense Phishing Defense Center have uncovered a phishing campaign exploiting Microsoft branding to deceive users. This campaign employs a combination of social engineering tactics and advanced overlays to harvest login credentials…
Recent analyses by the Cofense Phishing Defense Center have uncovered a phishing campaign exploiting Microsoft branding to deceive users. This campaign employs a combination of social engineering tactics and advanced overlays to harvest login credentials and persuade victims to call fraudulent support lines, granting attackers remote access.
The attack initiates with an email mimicking a payment notification from a fictitious entity, "Syria Rent a Car." The message entices recipients to click on an embedded link, redirecting them to a fake CAPTCHA challenge designed to appear legitimate.
Completing the CAPTCHA leads users to another page simulating a browser lockdown, displaying multiple pop-ups resembling Microsoft security alerts and claiming system compromise. This tactic mimics ransomware behavior, creating panic and urgency. Victims are prompted to call "Microsoft Support" via a displayed phone number.
Upon calling the number, victims connect with actors posing as Microsoft technicians. These actors employ high-pressure tactics to request account credentials or persuade users to install remote desktop software, allowing them to infiltrate networks, exfiltrate data, or deploy malware.
Analysis identified several malicious URLs used in the campaign, including:
Recent analyses by the Cofense Phishing Defense Center have uncovered a phishing campaign exploiting Microsoft branding to deceive users.
Initial links: hxxps://alphadogprinting[.]com/index.php?8jl9lz Variants hosted on: amormc[.]com IP addresses: 107[.]180[.]26[.]155, 184[.]168[.]97[.]153 Subsequent payload stages from domains like toruftuiov[.]com and highbourg[.]my[.]id
These indicators can assist defenders in blocking malicious traffic and identifying compromised clients.
Organizations should adopt the following measures:
Implement email filtering to inspect links for phishing domains and anomalies. Educate users to be skeptical of unsolicited payment notifications. Deploy endpoint security solutions to detect unusual browser behaviors. Maintain updated incident response playbooks for verifying legitimate support channels.
This campaign highlights the importance of layered defenses and continuous security awareness training to combat sophisticated phishing tactics.
Based on reporting by GBHackers.




