CypherLoc Scareware Targets Users with Fake Microsoft Support Scams

CypherLoc Scareware Targets Users with Fake Microsoft Support Scams

First seen 25 May 2026, 07:02 UTC GbhackersCybersecuritynewsFeeds.FeedburnerEscudodigitalblog.barracuda.com 88% similarity 68.2

Article Content

Browse articles
ThreatCluster

A new scareware kit named CypherLoc is being used by hackers to lock victims' browsers and direct them to fraudulent Microsoft support lines. This browser-locking scareware has been linked to approximately 2.8 million attacks since the beginning of 2026. CypherLoc operates in an encrypted manner, making it difficult for traditional security tools to detect. Security experts emphasize the need for robust anti-phishing and endpoint protections, as well as user education to combat this threat. The kit represents a significant escalation in browser-based attacks, posing risks to a wide range of internet users. Organizations are advised to implement stronger security measures to mitigate the impact of such threats.

Key Points: • CypherLoc scareware has been linked to 2.8 million attacks in 2026. • The kit locks browsers and tricks users into calling fake tech support. • Robust anti-phishing measures and user education are critical for defense.

ThreatCluster AI

Timeline

2026-01-01
CypherLoc scareware identified
Researchers first identified the CypherLoc kit as a significant browser-based threat targeting users.
Gbhackers
2026-05-25
2.8 million attacks reported
Barracuda researchers reported that CypherLoc has been involved in approximately 2.8 million attacks since early 2026.
Gbhackers
2026-05-25
Security recommendations issued
Experts recommend enhancing anti-phishing and endpoint protections to counteract CypherLoc threats.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story