Tech Support Scam Freezes Browsers

Stu Sjouwerman | Apr 30, 2019

fake-microsoft-support-page-640x249

Trend Micro has found a new tech support scam that abuses HTML’s Inline Frame element (iframe) along with authentication pop-ups to freeze victims’ browsers by trapping them in a type of loop. The web page imitates a Microsoft support page and presents users with two pop-ups.

One offers a phony Microsoft support phone number, while the other prompts users to log in. When users click the “cancel” button on the login prompt, they’ll be sent back to the initial URL, which will trigger another pop-up. This is achieved by setting the page’s showLogin as an iframe.

Trend Micro’s researchers think the scam is most likely distributed through advertisements. They emphasize that these scams rely on users’ fear arising from their seeming inability to recover their browsers.

“As has been highlighted in this new campaign, users can look out for suspicious characteristics of a webpage, such as unfamiliar URLs, pop-ups asking for authentication, or any sort of information and messages that raise panic and alarm,” they write.

In this case, users can close the browser from the task manager and then scan their systems for malware. New-school security awareness training can teach your employees to recognize the signs of these scams and remain calm when they encounter them. And remember, just close the browser. The scammers have got nothing on you.

Trend Micro has the story: https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/


Find out how affordable new-school security awareness training is for your organization. Get a quote now.

 
Get A Quote
Request A Demo
 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.