NG Solution Team
Cybersecurity

Tech support scam uses mouse movement to trigger fake alert

A tech support scam analysed by Netskope Threat Labs delivers ads on legitimate websites and waits for a mouse movement before displaying a full‑screen fake security alert that urges victims to call a support number.

How the tech support scam works

The chain begins with ads, mainly delivered through Google Ads, appearing on popular legitimate sites such as mapping, weather, sports and property websites. Netskope says the presence of those ads does not mean the sites have been compromised: the ads are served through ordinary advertising inventory. After a user clicks an ad, they see a loading screen and are taken to ShopEase, a fake online store that appears harmless.

The fake alert is only shown once the user moves the mouse. By waiting for that interaction, the campaign attempts to evade automated crawlers that inspect pages without generating mouse movement. According to Netskope, once movement is detected the kit decrypts a hidden C2 address, pulls down an encrypted payload (tailored to whether the victim is on Windows or a Mac), and assembles the fake alert within browser memory so no inspectable file crosses the network.

To make the situation appear urgent, the page switches to full‑screen mode, hides the address bar, tabs and cursor, and attempts to prevent users from using familiar keys and shortcuts to leave. It plays alarm sounds, slows down the browser and displays flashing messages warning users not to restart their computers and urging them to call the number on screen immediately.

Everything happens within the browser: the campaign does not encrypt files or take control of the operating system. Its aim is to convince the victim that urgent help is needed. During the call, scammers may try to charge for a nonexistent service, obtain login credentials or financial information, or persuade the victim to install a remote access tool.

Campaign reach and advice for users

Netskope Threat Labs tracked the campaign for two weeks and identified at least 619 organisations affected, 457 hosts associated with the scam infrastructure, more than 250 campaign identifiers and activity on 284 legitimate websites. The United States accounted for nearly 62% of the organisations identified, followed by Japan at 16% and Australia at 14%.

Netskope advises anyone who encounters such an alert not to call the displayed number, provide information or install software. To close the alert, users can hold down the Escape key for a few seconds or force the browser to quit using Windows Task Manager or the Force Quit option on macOS. When reopening the browser, they should avoid automatically restoring the previous session. The company also notes that a legitimate operating system or browser alert will never require users to call a number displayed in a pop‑up.

Related posts

SAP at a Crossroads: M&A Buzz and Maximum-Severity Security Alerts

Jessica Williams

Did OpenAI confirm its AI escaped the sandbox and hacked Hugging Face? Alternatives: – Did OpenAI admit its AI left the sandbox and hacked Hugging Face? – Has OpenAI confirmed its AI escaped sandbox controls and hacked Hugging Face?

Emily Brown

Leipzig-Halle airport diverts flights after security alert

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy