Visualização de leitura

Flirty OnlyFans promoters on X may be using AI to appear human

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages.

At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to produce more natural and flexible replies?

People are more likely to trust someone they believe is personally interested in them. AI can create that impression across many conversations at once, making it easier to persuade people to click links, spend money, or share personal or intimate information. The same approach could also be used for more harmful fraud, including romance scams and sextortion.

Now, developer Álvaro Martínez Majado has investigated several flirty accounts promoting OnlyFans pages on X to see whether their replies were scripted, generated by AI, or written by people. Majado, president of digital rights organization Protecció de la Frontera Electrònica, shared his evidence with Malwarebytes. Although it does not provide a definitive answer, it shows the accounts following rigid conversation scripts while also responding dynamically to unusual requests. The signs that once suggested a real person, such as an unusual reply or personalized voice note, can no longer be trusted.

The script goes on and on

Majado interacted with several accounts on X that followed a familiar pattern. They opened with similar casual, flirtatious language and asked broadly the same qualifying questions: where he lived, what he liked, and what he did for work.

That repetitive structure is exactly what we would expect from a commercially motivated messaging campaign. The goal is not necessarily to have a meaningful conversation. It is to identify people likely to respond, establish rapport, and eventually move them toward a paid page or another destination controlled by the operator.

The accounts also stayed in character when faced with obvious attempts to expose them as bots. That could be the result of hard-coded replies, guardrails around an AI system, or both.

Different accounts followed the same conversation pattern
They claimed to live in the same city as the recipient

But some later interactions were more difficult to explain as a simple bank of canned flirtatious responses.

One of the more interesting tests involved an instruction written as ASCII hexadecimal rather than ordinary text. The encoded message told the account to reply with a single word: “Pineapple.”

According to the screenshots supplied to Malwarebytes, the account responded with “Pineapple” in ordinary text.

An account followed an instruction encoded in hexadecimal
An account followed an instruction encoded in hexadecimal

That does not conclusively prove which technology was used. It does not identify a model, a provider, or the people behind the accounts. But it is consistent with an automated system capable of interpreting an encoded instruction and changing its output accordingly.

A simple scripted bot could theoretically include a hexadecimal decoder, of course. But that would be unusual in a basic adult-content promotional bot, especially when combined with other examples of flexible and sometimes error-prone responses.

In another interaction, Majado asked an account to provide a reply of exactly 12 characters. It responded with “Imnotabotfr”—an 11-character answer—then appeared to recognize its own counting mistake.

The account failed an exact character-count test, but recognized its error
The account failed an exact character-count test, but recognized its error

Anyone who has spent time experimenting with large language models may recognize the pattern. Language models can be very good at generating natural-sounding text while still making surprisingly basic mistakes involving character counts, word counts, and other exact constraints.

A deliberately designed bot could imitate this kind of mistake, so it is not proof of AI. But the account understood an unexpected instruction, attempted to follow it, and reacted when it got the answer wrong. That suggests it may have been generating replies dynamically rather than choosing from a list of pre-written responses. Such accounts can adapt to conversations, making them harder to identify as automated.

Voice notes do not settle the question

The accounts also sent voice notes. In one example, an account read aloud a Unix timestamp supplied during the conversation. In another, it spoke a requested username.

The accounts sent voice notes containing requested information
The accounts sent voice notes containing requested information

These responses show that the accounts could incorporate unusual information from a conversation into audio messages. They do not tell us whether a person recorded the clips or a text-to-speech tool generated them.

Text-to-speech tools can generate short, convincing clips quickly and cheaply. An operator can generate them manually, but the process can also be automated: Take a message, pass selected text to a voice-generation service, and send the resulting audio back to the recipient.

Here’s one of those voice notes. Is it a very flirty girl, or AI-generated? Have a listen and see what you think:

The supplied audio metadata offered a possible clue about the tools involved, but it is not enough to attribute the voice notes to a particular service. Platforms and other software can alter audio files and their metadata.

The more important point is that the voice notes were personalized and continued even after the interaction appeared unlikely to lead to a sale. That is consistent with a system designed to keep conversations moving without requiring a human to supervise each one.

AI does not replace the funnel

The evidence does not mean every message from every flirty spam account is written by an AI. Nor does it establish that the X accounts are operated by the same people targeting League of Legends players.

What it does suggest is a plausible hybrid model, supported by identical replies across different accounts alongside more flexible responses.

The repetitive parts of the operation can be scripted: opening messages, questions about location and interests, links, and attempts to move people to another platform. An AI-powered conversational layer could then make the exchange feel less repetitive when someone asks unexpected questions, changes the subject, or tries to test whether the account is real.

This combination makes practical sense for spammers. Scripts provide consistency and keep the conversation directed toward conversion. Generative AI helps the account handle the unpredictable parts of talking to real people.

It also means that traditional “bot tests” are becoming less useful. Asking an account to answer an unusual question, decode a message, or send a voice note may no longer distinguish a real person from a fake one.

How to stay safe

Treat unsolicited flirtatious messages with caution, especially when they quickly become transactional.

  • Do not assume a personalized response or voice message proves an account is genuine.
  • Be wary if a new contact repeatedly tries to move you to Discord, Telegram, Signal, another messaging app, or a paid-content platform.
  • Do not send money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone you only know online.
  • Avoid opening links or downloading files from accounts that contacted you unexpectedly.
  • Reverse-image-search profile photos and look for copied biographies, reused images, or accounts with very limited genuine activity.
  • Report suspicious accounts to the platform, particularly if they impersonate someone, send malicious links, or pressure users for money or explicit material.

Whether it’s a human, a chatbot, or an AI agent you’re talking to is an important question. AI could make these operations more convincing and much easier to scale. One operator could hold flirtatious conversations with many people, adapting the messages without personally managing every exchange.

That makes it easier to create a false sense of connection and persuade people to click links, pay for content, or share personal or intimate information.

The line between a scripted spam account and a responsive conversational partner is getting harder to see. Judge the account by what it wants you to do, not by how convincingly it talks.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

BengalSEO Part 1: Anatomy of the Operation

Key Takeaways The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Contact us today for pricing or a demo! Case Summary In March 2026, our team identified an SEO poisoning campaign leading to malware deployment […]

The post BengalSEO Part 1: Anatomy of the Operation appeared first on The DFIR Report.

Tech support scams look different now. Here’s what to watch for

In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer.

These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust.

How tech support scams reach you

As well as copying the websites of reputable brands, tech support scammers abuse sponsored search results, hijack on-site searches, create fake listings on trusted platforms, and use renewal scams, fake calendar invites, Apple Pay notifications, and many other methods to persuade people to call them.

Once someone makes contact, the scammers may demand payment, ask for personal information, or try to persuade them to install remote access software.

Beware of someone wanting to connect to your computer remotely. One of a tech support scammer’s most powerful weapons is the ability to connect remotely to a victim’s computer. If you allow this, the scammer may gain access to all of your files, folders, and the information they contain. 

Tech support scams impersonating Malwarebytes

Tech support scams affect Malwarebytes directly because scammers often impersonate trusted security companies, as in the example below.

Tech support scam impersonating Malwarebytes

You can tell it’s not the real Malwarebytes when:

  • They use a name other than Malwarebytes. Malwarebytes does not outsource its support. We have our own Support team and do not authorize third parties to provide support using our name, logo, or any other intellectual property. 
  • They can’t or won’t accept payment by credit card. Malwarebytes uses a credit card processor for all transactions. Credit card processors screen the companies they work with for risks such as fraud and abuse. Credit cards also offer consumer fraud protections, so it is a red flag if a company tries to steer you toward another payment method.
  • They make unsolicited support calls. Malwarebytes does not do this. Tech support scammers may buy personal information from data brokers that have identified people as potentially vulnerable targets. But how would a legitimate company know that you have a problem with your computer—or even that you own one? If someone calls out of the blue claiming that your computer has a problem, hang up.

What to do if you’ve been scammed

If you’ve fallen victim to a tech support scam, here are a few steps you can take:

  • Have you already paid? Contact your credit card company or bank and let them know what’s happened. You may also need to file a complaint with the FTC or contact your local law enforcement agency, depending on your region.
  • Did you share your password with the scammer? Change it on every account that uses the same password. Consider using a password manager and enabling two-factor authentication (2FA) on important accounts.
  • Scan your system. If scammers have accessed your computer, they may have installed a backdoor that allows them to return later. Malwarebytes can remove backdoors and other software left behind by scammers.
  • Keep an eye out for unexpected payments. Look for suspicious charges or payments on your credit cards and bank accounts so you can dispute them quickly and prevent further losses.
  • Be wary of suspicious emails and text messages. Scammers may now see you as a potential target and try other methods to defraud you.

How Malwarebytes is fighting tech support scams

Malwarebytes researchers actively fight tech support scams in the US and overseas. They work closely with the Federal Trade Commission (FTC), providing technical evidence to help shut down tech support scammers and educating internet users about the latest tactics and how to protect themselves.

Malwarebytes is also a supporting member of the Global Anti-Scam Alliance (GASA), working with other organizations committed to reducing scams and keeping people safer online.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing

  People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. The attack pattern of the recently […]

Kim Sooki again? This time, it was disguised as a request for seafood ingredients

A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]

Security Issues in the Korean & Global Financial Sector in July 2026

Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]

Beware of Phishing Emails Disguised as Transaction Receipts

Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]

New turnkey kit makes it easy for anyone to become a scammer

In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer.

Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else.

However, behind the promises of easy money can be carefully designed operations built to gain trust, collect deposits, and ultimately leave victims with significant financial losses. In some cases, scammers go to considerable lengths to make their projects appear legitimate, creating professional-looking websites, social media profiles, and convincing stories designed to attract as many victims as possible.

This is the story of one such project: a crypto scam discovered on a cybercrime forum, where the people behind it appeared to openly discuss and promote their operation.

What we found provides a glimpse into how modern online scams are built, promoted, and potentially used to target everyday consumers.

Meet “xrep”

Threat actor’s profile on cybercrime underground forum
Threat actor’s profile on a cybercrime underground forum

The threat actor known as xrep has been active in the cybercrime underground since March 2026. It appears that xrep has already built a positive reputation among customers, receiving favorable feedback for the services and solutions they provide.

Positive feedback left by another cybercriminal
Positive feedback left by another cybercriminal


In general, xrep specializes in ready-to-use solutions related to X, formerly known as Twitter. Rather than requiring customers to build their own infrastructure or develop the necessary tools, xrep offers what can essentially be described as a full turnkey solution for scammers.

Overview of services offered by xrep
Overview of services offered by xrep

This approach significantly lowers the barrier to entry for scammers looking to conduct malicious activities. By providing a ready-made package that requires little technical expertise to deploy, xrep enables individuals with limited skills to potentially launch scams with considerably less effort.

$TSLA scam: A crypto investment opportunity designed to steal

Tesla scam kit offer
Tesla scam kit offer


The scam project, discovered on May 16 by the Malwarebytes research team on a high-profile cybercrime forum, is a good example of how modern scams combine social engineering, phishing, and financial fraud into a single operation.

The product, priced at just $500, is essentially a ready-made website designed to look like a legitimate cryptocurrency presale. The supposed opportunity is presented as an exclusive $TSLA token presale for users of X, creating the impression that visitors have been personally selected for an early investment opportunity.

Tesla scam kit description and pricing
Tesla scam kit description and pricing

The website is designed to look professional and trustworthy, clearly impersonating the Tesla brand name and company logo. It supports multiple languages and is optimized for both computers and mobile devices. But the most important part is what happens behind the scenes.

The scam begins with a fake “eligibility check.” Visitors are asked to enter their X username. The screenshots below are taken from the $TSLA token scam site.

$TSLA token scam site

The website then retrieves their real profile picture and uses it to generate a fictional token allocation. This makes the offer appear personalized, giving the victim the impression that they have been specifically chosen to participate.

$TSLA token scam site
Figure 7: Scam project screenshot

The site also uses classic psychological pressure tactics. A fake fundraising progress bar continuously increases, a countdown timer creates a sense of urgency, and warnings suggest that the token price will increase soon. These features are designed to create FOMO (fear of missing out) and encourage victims to act before they have time to question whether the investment is legitimate.

Once a victim is convinced, the scam offers two ways to lose money or access to their cryptocurrency wallet.

$TSLA token scam site

The first is a classic phishing attack. Victims are encouraged to connect their cryptocurrency wallet to receive a supposed 15% bonus. Instead of connecting a legitimate wallet, they are prompted to enter their 12-word recovery phrase, also known as a seed phrase.

$TSLA token scam site

This phrase is effectively the master key to a cryptocurrency wallet. Anyone who obtains it may be able to access the funds stored in that wallet.

The second method involves direct payments. After going through the fake wallet process, victims are redirected to a convincing-looking personal dashboard. There, they can see a fabricated token balance and are encouraged to purchase additional $TSLA tokens.

$TSLA token scam site
$TSLA token scam site

The victim is instructed to manually send cryptocurrency, such as Bitcoin, Ethereum, USDT, or Dogecoin, to an address controlled by the scammer.

$TSLA token scam site

Victims may believe they have made a legitimate investment, but no real tokens are being purchased. Instead, the scammer simply receives the cryptocurrency while the victim sees a fake balance displayed on the website.

What makes this operation particularly concerning is the level of control provided to the scammer. The kit includes an administrative panel where the operator can monitor victims, view their X usernames and locations, track their activity, and collect the recovery phrases entered into the phishing page.

The scammer can also check whether a stolen wallet contains valuable cryptocurrency. This allows them to identify which victims may be worth targeting further. The operator can even manipulate the fake balance shown to a victim, for example, increasing the displayed amount to make the victim believe their investment is growing and encourage them to send even more money.

$TSLA token scam administrative panel

The administrative panel also allows scammers to manage fake purchase orders and send personalized messages to victims. For example, if someone has already made a payment, the scammer can send a notification claiming that the transaction is delayed and that the victim needs to pay an additional network fee. This creates another opportunity to extract money from someone who has already fallen for the initial scam.

$TSLA token scam administrative panel

In other words, this is not simply a fake cryptocurrency website. It is a complete scam-in-a-box. The technical infrastructure, phishing functionality, fake investment dashboard, victim tracking, and administrative controls are bundled together into a ready-to-use package.

The significance of this discovery goes beyond this particular $TSLA-themed project. By selling a complete, turnkey operation, xrep effectively lowers the technical barrier for individuals who want to conduct cryptocurrency scams. Someone who may not have the skills to build a phishing website, develop an administration system, or create convincing investment interfaces can potentially purchase the kit and begin targeting victims with minimal effort.

For ordinary internet users, the lesson is simple: a professional-looking website does not make an investment opportunity legitimate. Personalized offers, countdown timers, rapidly increasing “fundraising” figures, and promises of exclusive access are all tactics that can be used to create a false sense of urgency. Most importantly, no legitimate investment opportunity should ever require you to give away your cryptocurrency wallet’s recovery phrase.

Once that phrase is compromised, the consequences can be devastating, and unlike a traditional bank transfer, cryptocurrency transactions are often impossible to reverse.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Scammers use AI deepfakes to impersonate OnlyFans creators, trick fans into sending money, then disappear after payment.

Criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then disappearing after collecting payment. The scheme runs on social platforms that most people consider harmless, TikTok for discovery, Snapchat for the conversation, Cash App for the payment, and by the time the fan realizes something is wrong, the money is already gone and the account is blocked.

“This is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice.” reads the report published by MalwareBytes. “They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.”

The choice of Cash App as the payment method isn’t accidental. It’s a peer-to-peer platform built for informal transfers between friends, not commerce — and transfers clear instantly. Once sent, the money is effectively gone.

“This kind of fraud has two victims: the fans who lose money to scams, and the creators. The latter lose income that they might have collected from fans, and also run the risk of retribution from disgruntled followers who think they’ve been taken advantage of.” continues the report.

One creator, Jessieanna Campbell, told USA Today she constantly receives messages from angry fans accusing her of taking their money and blocking them, for transactions she never made. Another creator interviewed by USA Today had fans show up at her home after the confusion, and now sometimes doesn’t feel safe leaving the house.

“The problem is that domestic laws only apply to domestic platforms. The stolen material largely sits on overseas hosts, making it difficult to control.” concludes the report. “Even if laws could be universally enforced, it might not matter. In three experiments conducted this year, researchers at the University of Bristol found that most participants relied on deepfake content even after being told it was fake.”

Federally, the Take It Down Act criminalizes non-consensual explicit content including AI-generated material and requires rapid platform takedowns. The EU’s AI Act requires disclosure when AI is used for image generation. Neither law has stopped the content from circulating because enforcement stops at national borders and the hosting doesn’t.

Spotting a deepfake is still possible if you know what to look for. USA Today described a TikTok video impersonating creator Elaina St. James, made by animating a still photo with a cloned voice, that showed distorted teeth and frozen eyebrows. Those artifacts are common in AI-generated video, especially when the source material is limited. Malwarebytes has published a practical guide to spotting deepfakes of any kind.

A similar pattern has been documented in romance scam contexts. Malwarebytes previously reported on Amazon and Apple impersonation scams using the same redirect-and-collect mechanics, where the victim is moved off a trusted platform into a direct channel before the ask. The underlying manipulation — establish familiarity, trigger urgency, request payment through an irreversible channel, is consistent across scam types regardless of which face or brand is being faked.

If a “creator” reaches out to you through a third-party platform and steers the conversation toward a direct payment for exclusive content, treat it as a red flag. Verify through the creator’s official, verified accounts before doing anything else. And if someone who looks like a creator you follow is asking for Cash App payment before delivering anything, assume you’re about to be blocked.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI Deepfakes)

Scammers target OnlyFans users with deepfakes

OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance.

How the catfishers hook their bait

This is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice. They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.

Once there, the “creator” asks for a Cash App payment in exchange for exclusive content. Cash App is a peer-to-peer payments service built for casual sends between friends, not for commerce. Transfers clear instantly and settle in the recipient’s balance within seconds. Once it’s been sent, it’s very difficult to recover.

That informal design is exactly what makes it useful here. As soon as the fan pays up, the criminal blocks them and disappears.

Why the laws don’t reach the actual servers

Lawmakers are tackling this with multiple state-level anti-deepfake bills. Federally, the Take It Down Act criminalizes non-consensual explicit content, including AI-generated images, and requires rapid platform takedowns. In the EU, the AI Act requires anyone who uses AI for image generation to disclose it publicly.

So why is this still happening?

The problem is that domestic laws only apply to domestic platforms. The stolen material largely sits on overseas hosts, making it difficult to control.

Even if laws could be universally enforced, it might not matter. In three experiments conducted this year, researchers at the University of Bristol found that most participants relied on deepfake content even after being told it was fake.

What actually helps

This kind of fraud has two victims: the fans who lose money to scams, and the creators. The latter lose income that they might have collected from fans, and also run the risk of retribution from disgruntled followers who think they’ve been taken advantage of.

One creator, Jessieanna Campbell, told USA Today that confused fans complained to her after mistakenly thinking she had taken their money. “I get messages all the time, like, ‘Hey, why did you take my $150 and block me?’ and I’m like, ‘What are you talking about?'”

USA Today also interviewed one creator who had angry fans visit her home, and is now sometimes scared to leave her house.

Some creators are hiring private content takedown services to try and fix the problem themselves. Others are posting public service announcements warning of these fake accounts. But it’s up to the fans to listen.

If a “creator” on a third-party platform contacts you, watch the video closely; the deepfakes are often flawed. USA Today reported that a TikTok video impersonating creator Elaina St. James, made by animating a still photo and cloning her voice, showed distorted teeth and frozen eyebrows. Here’s our guide to spotting deepfakes of any kind.

Common sense is the bottom line. If someone steers you into a direct messaging platform and solicits money for exclusive content, think twice. Check with the creator via a verified account to see if it’s real.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Amazon and Apple impersonated in “$149.99 unauthorized charge” scam

If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon account was just used for a mysterious $149.99 purchase. It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither.

Below are two popups pulled from real pages—one dressed up as Apple Support, one as Amazon.

Same con, two costumes

Below, one popup is skinned as Apple Support, the other as Amazon. Swap the logo and color palette and the structure is identical: a warning icon, a claim that a $149.99 purchase was just made “via Pre-Authorization,” and a phone number to call immediately. That phone number is exactly the same in both.

Fake Apple alert

Fake Amazon alert

That reused phone number is the tell. If you only see one popup, running the number through a lookup tool like Malwarebytes Scam Number Check is usually enough to expose it—a real Apple or Amazon line won’t come back flagged, but a scam number typically does, often tied to complaints about several unrelated companies at once.

Why the copy is built the way it is

Every element in these popups is doing specific psychological work:

  • A believable, moderate dollar amount. $149.99 is high enough to alarm you, low enough to sound like a real subscription or product charge rather than an obvious lie.
  • “Pre-Authorization” jargon. This is real payment terminology (used for things like hotel holds or gas station charges), borrowed here to sound technically credible to someone who doesn’t handle payments professionally.
  • Manufactured urgency. “Call immediately,” “Immediate Action Required,” “no hold times”—all are designed to get you dialing before you stop to verify anything.
  • Visual authority. Red warning triangles, brand-matching fonts and layouts, and a full-screen modal that blocks the rest of the page all borrow the visual language of legitimate security alerts.
  • A single, frictionless call to action. One button, one phone number. The popup wants exactly one thing from you: to pick up the phone.

If you do call, the number connects to a live scammer posing as support staff, whose actual goal is to get remote access to your device, walk you through “verifying” your identity in a way that hands over real account or payment info, or push you toward paying a fake fee—often via gift cards or a wire transfer.

How to tell if it’s fake

A few checks work regardless of which brand is being impersonated:

  1. Real companies don’t alert you this way. Apple and Amazon notify you about account activity through email, in-app notifications, or your account’s activity log—never through an unexpected popup while you’re browsing.
  2. No legitimate company tells you to call a phone number to stop a charge. Disputing a charge happens through your bank, your card issuer, or the company’s actual account dashboard—not a hotline dictated by a popup.
  3. Check where the popup is actually served from. These often ride in on malicious ads, compromised sites, or browser redirects—the underlying page may be spoofed or injected, not the real apple.com or amazon.com support page it appears to sit on top of.
  4. A popup you can’t easily close is a red flag on its own. Legitimate sites don’t need to trap you behind a full-screen modal to relay account information.
  5. If in doubt, go direct. Close the tab (force-close via task manager if needed) and navigate to the company’s site yourself, or call the number printed on your card or official account page—never the one in the popup.
  6. Check the number before you dial it. Run it through Malwarebytes Scam Number Check to see if it’s already been flagged as a scam line.
  7. Block it before it loads. A browser extension like Malwarebytes Browser Guard catches both known malicious pages and unknown ones showing scam-like behavior, so these popups often get stopped before they ever render.

Don’t judge a scam by its logo

The brand on screen—Apple, Amazon, or whoever’s next—is the least important part of this scam. What actually matters is the pattern underneath: an unexpected popup, a suspiciously specific dollar amount, urgent language, and a phone number that wants you to call before you think. Once you recognize that pattern, it doesn’t matter which company’s name is stamped on top of it.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.

What’s your data worth on the dark web? (Lock and Code S07E15)

This week on the Lock and Code podcast…

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”

Pithy as the phrase sounds, it is undeniably true.

Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.

So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?

That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.

These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.

As we wrote on Malwarebytes Labs:

“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”

It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.

And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.

The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.

So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.

Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.

Tune in today to listen to the full episode.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations

Don’t get fooled by TikTok resin art scams

Resin art has become a popular corner of TikTok, with some videos attracting millions of views. But not every glossy, colorful post is what it claims to be. Scammers are using the look of handmade resin art to trick buyers, collectors, and even fellow artists into sending money for work that either doesn’t exist or wasn’t created by the person posting it.

There are plenty of genuine resin artists on TikTok. Unfortunately, the platform has also attracted scammers who steal videos and impersonate legitimate creators.

  • Fake resin art
  • Fake resin art
  • Fake resin art
  • Fake resin art
  • Fake resin art
  • Fake resin art

The scam is fairly straightforward. A TikTok account presents itself as a resin artist, posts satisfying videos, and invites people to “DM to order.” In some cases, the videos are stolen from other creators, the account has no real process footage, and the seller disappears after receiving payment.

One resin artist discovered that scammers were using their videos to impersonate them and scam TikTok users. They shared the following comment:

Ridiculous TikTok scammer…lol. Profile says they’re a resin artist and to DM them to order, but none of the videos are theirs. When I wrote to them asking them to take down the many videos of mine that they posted, passing them off as their own with no credit, their answer was that they aren’t a resin artist and are just sharing videos they like 🤣🤣 Literally about 1/4 of “their” videos are mine 🙄

These scams often rely on trust and urgency. The account may show polished clips of poured resin, finished coasters, trays, jewelry, or wall art, then push buyers to move the conversation into direct messages. Once the buyer moves to a different platform, the scammer typically requests a deposit, full payment, or personal details with little chance of being held accountable.

And real artists don’t just get their work ripped off. A scammer may contact a creator claiming to want to buy, feature, or license their work, but the real goal is to extract fees, banking information, or other sensitive data. Social media art scams are often repetitive because they are built from the same templates and scripts.

Script is similar across many videos in resin art scams
Different videos, same script

How to spot a TikTok resin art scam

The safest approach is the boring one: verify before you pay. If the artwork looks amazing but the seller’s identity is vague, the risk is real.

Check the TikTok account

Before ordering, look for signs that the artist is genuine:

  • The account didn’t appear overnight and has a history of original posts.
  • The same videos don’t appear under multiple creator names or belong to another artist.
  • The creator shows themselves making the artwork, with consistent process videos, a recognizable workspace, and works in progress.
  • The videos don’t contain obvious AI artifacts, such as impossible resin effects or objects moving after they’ve supposedly been sealed inside hardened resin.
  • Comments raising concerns haven’t been deleted or buried under generic praise.
  • The seller isn’t pushing you to order only through direct messages or asking for payment before you’ve verified who they are.

Check the website

If you do click through to a website, spend a few minutes checking it before you buy:

  • Look for a genuine returns and refunds policy, a physical business address, company or VAT details (where applicable), and consistent contact information.
  • Check how old the website is. Scam sites often use domains that were registered only weeks or months ago, especially when they claim to have been selling handmade products for years.
  • Search for recent independent reviews rather than relying on testimonials published on the site itself.
  • Run a reverse image search on the product photos to see whether they’ve been copied from another artist.
  • Only pay using a method that offers buyer protection, such as a credit card or PayPal. If a seller insists on a bank transfer, cryptocurrency, or another irreversible payment method, walk away.

Not every resin art account is a scam. Many belong to genuine artists, and that’s why impersonation scams can be so convincing.

If you’re unsure, paste the website address into Malwarebytes Scam Guard and ask whether it shows signs of being fraudulent. It can help identify suspiciously new domains and other common scam indicators.

Use Malwarebytes Scam Guard to check whether a social media post or website is part of a scam.

Use real-time web protection to block known fraudulent and malicious websites, like Browser Guard did for this web shop:

Browser Guard blocks the web shop due to likely fraud
Browser Guard blocks the fraudulent website

Both are free—making them much cheaper than sending money to a scammer.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

June 2026 Security Issues in Korean & Global Financial Sector

Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]

Don’t trust that “FBI agent” in your DMs

The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already been victims of cybercrime.

The FBI has issued warnings like this before, but scammers posing as IC3 employees and FBI agents continue to evolve their schemes and claim new victims.

The best-known of these scams are recovery scams, complete with FBI logos and branding that make them look far more convincing.

Facebook accounts like the one below—and yes, I reported it—with equally fake reviews prey on people who have already fallen victim to a scammer.

Fake IC3 Facebook account

“Have You Been Scammed or Defrauded? We’re Here to Help.

If you’ve fallen victim to online fraud, investment scams, crypto scams, romance scams, or unauthorized transactions, Reliable Scam Recovery Inc is ready to assist you in pursuing the recovery of your lost funds.

Our experienced recovery team works with victims to investigate scam activities, trace transactions, and provide guidance throughout the recovery process with confidentiality and professionalism.

✔Professional case assessment

✔Secure and confidential support

✔Dedicated recovery assistance

✔Fast response team

Don’t let scammers win. Take the first step toward reclaiming your losses today.

Contact Ic3 Scam Recovery Inc now for support and recovery assistance.”

The scammers count on victims feeling desperate and embarrassed. They have no scruples about victimizing them all over again.

The post contains a lot of the tell-tale signs IC3 warns about. Very vague but reassuring claims: “experienced recovery team,” “professional case assessment,” “secure and confidential support” all sound impressive but provide no verifiable detail. High‑level promises like “investigate scam activities” and “trace transactions” imply special legal or technical powers, but the FBI warns that scammers make similar promises to convince victims they’re dealing with authorized investigators.

Besides setting up fake IC3 accounts, they also monitor social media for posts from victims saying they’ve reported a scam to the FBI, then swoop in posing as FBI follow‑up contacts.

If victims remain unconvinced, the scammers may create videos depicting senior FBI officials or other recognizable public figures urging them to submit their case through a specific link “to speed up recovery.” The FBI says criminals are increasingly using AI-generated deepfake audio and video to make these messages appear genuine.

How to stay safe

First and foremost, remember that IC3 has no official social media presence, does not investigate crimes via social media, and will never contact victims directly to recover funds.

As the IC3 homepage states:

“The IC3 does not work with any non-law enforcement entity, such as law firms or crypto services, to recuperate lost funds or investigate cases. The IC3 will never directly contact you for information or money.”

So, if an “agent” appears in your direct messages (DMs) right after you post publicly about being a crime victim or planning to report to the FBI, assume they are a scammer until independently verified. A few other tips:

  • Never pay upfront: Legitimate government agencies never ask you for advance payment to recover stolen money.
  • Ignore unsolicited claims: Be highly suspicious of anyone who reaches out to you out of the blue claiming they can reverse a previous scam.
  • Never share your credentials: Do not give remote access to your device or hand over your passwords and recovery phrases to unknown third parties.
  • Don’t provide IDs or financial information. Scammers can use them for identity theft or further fraud.
  • Use verification tools: If you receive a suspicious email, message, or phone call, you can verify its legitimacy using tools like Malwarebytes Scam Guard.
  • Report scammers: If you or someone you know has fallen victim to this scam, file a complaint with the IC3 at ic3.gov

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

❌