Scareware
Scareware is malicious software or fake alerts that frighten victims into installing malware or paying for useless 'security' products by faking an infection.
Scareware is a social engineering technique that manufactures fear — typically a fake virus alert, a flashing "your computer is infected" pop-up, or a full-screen browser lock — to pressure the victim into a harmful action: downloading fake antivirus software, paying for a useless cleanup tool, or calling a fraudulent "support" number. The threat it warns about does not exist; the scareware itself is the attack.
How it works
Scareware usually arrives through malicious ads, compromised websites, or poisoned search results. The victim lands on a page that suddenly displays an alarming system-style alert, often mimicking Windows Defender, macOS, or a well-known antivirus brand. Common pressure tactics include:
- Fake scan animations that "discover" dozens of infections in seconds, complete with progress bars and file names.
- Browser lockers — full-screen pages with JavaScript that hides the cursor or re-opens dialogs, making the browser appear frozen until the victim complies.
- Countdown timers and alarm sounds claiming files will be deleted or the machine reported unless the user acts immediately.
- Tech support numbers connecting the victim to a call center that requests remote access or payment — the same infrastructure behind callback phishing.
The payoff varies: payment card details harvested through a fake purchase, remote-access tools installed under the guise of "cleaning," or actual malware delivered as the promised antivirus. In corporate environments, the remote-access variant is the most dangerous, because it hands an attacker an interactive session on a managed endpoint.
How to defend against it
- Teach the tell: real security software does not demand payment through browser pop-ups, and browsers themselves do not scan for viruses. Any alert that asks the user to call a number or install something immediately is hostile.
- Make closing safe and easy. Train employees to close the browser via the task manager if a page will not release them, and to report the incident rather than "fix" it themselves — reporting behavior is a core signal in a human risk program.
- Block the delivery channels with ad-blocking or DNS filtering on managed endpoints, and restrict who can install software or run remote-access tools.
- Simulate the scenario. Fear-based lures behave differently from curiosity-based ones; security awareness training that includes scareware examples builds recognition before the real pop-up appears.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo