US Secret Service court documents reveal new tactics in antivirus renewal phishing scam

A bank card skewered on the end of a fishhook in front of a white computer keyboard.
(Image credit: Getty Images / Peter Dazeley)

New documents submitted by the US Secret Service as part of a recent seizure warrant have revealed an all-new form of phishing scam techniques centered around antivirus renewal.

In this instance, a scammer stole $34,000 after emailing the victim stating that there was an auto-renewal of $349.95 on their account that would be charged unless cancelled.

The victim then called the scammers to do so, and was told to provide remote access to their laptop in order to ensure the refund went through.

 Executed Warrant 

The warrant, submitted by Special Agent Jollif of the United States Secret Service, hopes to return the $34,000 to the victim as the funds are currently suspended in a JP Morgan Chase suspense account due to the detection of a potentially fraudulent transaction.

The scammer, identified as “Bingsong Zhou” in the warrant application, tricked their victim into installing remote access software which Zhou then used to transfer the funds from the victims savings account into their own while disguising their actions under an overlaid bluescreen.

Jollif stated in the document that while tactics like this have existed for several years, they are seeing increasing use. In the document, Jollif states, “Criminals are posing as legitimate representatives of real companies and, through a series of impersonations, are negotiating the transfer of funds via wire transfers from a victim bank account to an account controlled by the criminal.

“Once the criminal receives the fraudulently obtained funds, it is common practice to move the funds rapidly between accounts to prevent law enforcement detection.”

Via BleepingComputer

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
Shopping scams
New wave of sextortion scams uses personal details and images to intimidate targets while bypassing traditional security measures
Representational image of a hacker
Email scams vs Phishing - is there a difference?
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
An abstract image of a lock against a digital background, denoting cybersecurity.
This AI scam detector could save you thousands by stopping scammers before they reach you, but it's only free if you're a McAfee customer
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Latest in Pro
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
HP Series 7 Pro 734pm during our review
I reviewed HP's Series 7 Pro 734pm and I'm obsessed with the sheer connectivity of this widescreen monitor
TSMC
TSMC announces huge US investment to boost AI development
Google Pixel 9 Pro
Google Password Manager may be set to introduce a nuclear option for its Android app
Latest in News
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Guitar Hero Mobile
Activision shares first look at Guitar Hero Mobile and, yeah, it looks like AI slop
Web DDoS attacks see major surge as AI allows more powerful attacks
Pulchra Fellini in Zenless Zone Zero.
Zenless Zone Zero Version 1.6 will finally let you play as a furry gunslinger
Two hands holding the Tecno Spark Slim phone
The world’s thinnest phone was just revealed, but a new iPhone 17 Air leak suggests it could be even slimmer
Polish space agency says it was hit by a cyberattack