A new and particularly convincing phishing has emerged, leveraging Microsoft’s name and corporate identity to trick unsuspecting users. According to an analysis by Cofense, this campaign falls into the category of “tech support scams,” i.e. scams that pretend to be official technical support notifications with the aim of stealing credentials or remotely accessing victims’ computers.

The scam that «wears» the mask of Microsoft
Victims receive a seemingly authentic email, which includes the official Microsoft logo and a title such as “Important Security Notice” or “Pending Financial Transaction.” The message invites recipients to click on a link in order to “verify their details” or “instantly resolve an account issue.”
This technique exploits the trust Microsoft enjoys, leading many users to believe that this is a legitimate notification. Once the user follows the link, it begins a chain of well-placed redirects that ends up on a fake CAPTCHA — a classic tactic to lend credibility to the process.
See also: Have I Been Pwned: Prosper breach affects 17.6 million people
From the fake CAPTCHA to «locked» browser
After “verification,” the unsuspecting user is taken to a page that mimics the Microsoft Edge or Windows environment, where the browser appears to have locked down. Pop-ups appear on the screen with supposed security alerts, claiming that “the system is infected” or “a serious breach has been detected.”
The psychological pressure is intense: the victim sees their mouse unresponsive, hears warning beeps, and reads messages urging them to call a technical support phone number.

In reality, this number belongs to the scammers themselves. During the call, the supposed “technician” instructs the user to install a remote desktop tool, such as AnyDesk or TeamViewer, to “fix” the problem. This gives the perpetrators computer victim’s, as well as stored files, passwords, and financial information.
The infection mechanism
The campaign is based on a chain of URL redirects. The initial sites, such as hxxps://alphadogprinting.com/index.php?8jl9lz and hxxps://amormc.com/index.php?ndv5f1, act as intermediate redirectors. From there, the victim is moved to payload domains, such as hxxps://my.toruftuiov.com/... or hxxps://deprivy.stified.sbs/proc.php, which host the malicious script.
See also: North Korean hackers use EtherHiding to hide malware in Blockchain Smart Contracts
This script manipulates the browser's DOM, disables mouse movement capability and creates a false impression “freeze” of the browsing program. Although the “lock” can be easily bypassed with the ESC key, few users know it, thus being led into the trap of telephone communication.
The new generation of social engineering
Cofense researchers highlight that the perpetrators have significantly advanced their social engineering techniques. The campaign combines payment decoys, realistic UI overlays, and multiple stages of deception, creating a multi-layered psychological effect that makes the scam seem completely legitimate.
The use of corporate brands, combined with interface elements reminiscent of Windows, disorients even experienced users, especially those who work remotely and face security alerts.

How to protect yourself
Experts recommend:
- Never call support numbers that appear suddenly in pop-up windows.
- Close the browser immediately with the ESC key or via Task Manager.
- Check the address bar for suspicious URLs.
- And especially, ignore emails that request immediate action or account details.
Microsoft never contacts users in this way nor requests phone contact for security issues.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Phishing campaign misuses LastPass name – Company denies breach
This new campaign confirms that tech support scams continue to evolve, adopting increasingly realistic social engineering tricks. In an era where users are bombarded with notifications and digital suggestions, vigilance and critical thinking remain the first line of defense against cybercriminals.
