Fake Antivirus Browser Lock Scam
Incident Timeline
Time: January 30, 2024, 8:45 PM
Activity: Researching travel destinations
Site Visited: Legitimate travel blog (likely compromised)
Trigger: Clicked on image gallery
Attack Sequence
Initial Infection
- Pop-up: "CRITICAL VIRUS DETECTED" covering entire screen
- Audio: Loud alarm sound (couldn't be muted)
- Visual: Fake Windows Defender interface with moving scan
- Lock: Browser controls disabled, Alt+F4 blocked
Fake Alert Content
- "Microsoft Security Alert": Windows Defender has detected 7 trojans
- "Threat Level": Severe (red exclamation marks)
- "Affected Files": System32 files listed
- "Action Required": Call support immediately: 1-800-XXX-XXXX
- "Warning": Do not close browser or data will be corrupted
Technical Analysis
Malicious Code
- Method: JavaScript browser lock
- Escape Prevention:
- Disabled right-click
- Intercepted keyboard shortcuts
- Prevented tab/window closing
- Fake warning on escape attempts
- Persistence: Local storage used to maintain lock
Domain Investigation
- Compromised Site: travel-adventures-blog.com
- Injection Point: Ad network script
- Payload Source: malicious-cdn[.]com/av-popup.js
- Duration: Active for 3 hours before cleanup
Resolution Steps
Immediate Actions
- Browser Closure: Task Manager → End Chrome process
- System Scan: Ran Malwarebytes (no threats found)
- Browser Reset: Cleared cache, cookies, reset settings
- Number Research: Found reports of fake Microsoft support
Follow-up Actions
- Reporting:
- Notified travel blog owner
- Reported to Google Safe Browsing
- Submitted to Microsoft Security
- Filed Quiet-Report
- Protection:
- Installed uBlock Origin
- Updated browser extensions
- Enabled enhanced protection in Chrome
Impact Assessment
Time Lost: 45 minutes (recovery + reporting)
System Integrity: Verified clean (no malware)
Data Security: No data compromised
Financial Risk: $0 (didn't call number)
What Happens If You Call
Based on other reports:
- Remote access installation
- Fake virus "discovery"
- Pressure to pay $299-499
- Possible real malware installation
- Credit card information theft
Prevention Recommendations
- Use ad blocker with malware protection
- Never call numbers from pop-ups
- Task Manager can always close browsers
- Legitimate antivirus doesn't work this way
- Keep browser and extensions updated