The old version of this scam was easy to laugh at. Your browser window locks up, a red banner screams that your PC is infected, a robotic voice starts talking, and somewhere on the page there is a number to call right now. Nobody had to teach you that was fake. It looked fake.

That version is going away, and the replacement is a lot quieter. Malwarebytes Labs wrote at the start of September that these scams "used to rely mainly on browser locks and fake virus warnings", and that criminals now copy the websites of reputable brands and pretend to work for a trusted technology or security company. Same goal, better costume.

What actually changed?

Two things. The page got better, and the way you arrive at it got more ordinary.

According to the same Malwarebytes piece, as well as copying the websites of reputable brands, tech support scammers abuse sponsored search results, hijack on-site searches, create fake listings on trusted platforms, and use renewal scams, fake calendar invites and Apple Pay notifications to persuade people to call them. Read that list again. Not one of those arrives looking like a threat. A sponsored result sits at the top of a normal search. A calendar invite lands in your calendar. A renewal notice is the most boring email in the world.

So the moment where your instincts used to fire, the screaming pop-up, is gone. You are just on a website. And the website looks right.

A look is the cheapest part of a website to copy. Logo, colours, fonts, layout, support chat widget, even a real-looking phone number: all of it is copyable in an afternoon. The domain is the one part that cannot be duplicated, because someone had to register it, and only one owner can hold it.

Why does a copied page work so well?

Because we check brands with our eyes, and the eyes were given exactly what they expect. Nothing on a well-built copy is "off". There is no typo to catch, no stretched logo, no weird stock photo. First of all, the design is usually pulled straight from the real site, so it is not similar to the original, it is the original, minus the ownership.

And then there is the phone number. A number on a page feels like proof, because a human will answer. Someone does answer. That is the business model 😅

Where does the check still work?

In the address bar. Not on the page, not in the logo, not in the phone number. The address bar is the only element on your screen that the scammer does not control the wording of.

Here is the shape to look for. Read the address from the first single slash backwards, and take the two words right before the last dot.

Realmicrosoft.com/supportthe two words before the first slash are microsoft.com
Fakemicrosoft-support-alert.example[.]comthe real owner here is example.com, and "microsoft" is just decoration in front of it

A brand name can appear anywhere in an address: in front of the real domain, after it, in the path, in the page title. It means nothing in those positions. Only the part immediately before the last dot, plus that last dot's ending, tells you who owns the place.

What about the CAPTCHA that asks you to paste something?

This one deserves its own paragraph, because it is spreading and it is not obvious. Malwarebytes Labs described a Windows campaign, which Microsoft calls TerminalFix: a visitor sees what looks like a Cloudflare CAPTCHA, clicking it silently copies a command to the clipboard, and the visitor is then told to paste and run it to prove they are human.

The rule here is simple and worth memorising. A real CAPTCHA may ask you to tick a box or pick out the traffic lights. It will never ask you to open Run, Terminal, Command Prompt or PowerShell and paste a command in. However convincing the brand on that box looks, that instruction alone is the whole answer.

So what do you do when a support page looks right?

  1. Stop before you call. A phone number on a web page is not a credential. It proves only that the page has a phone number on it.
  2. Copy the address, don't retype it. Retyping quietly corrects whatever trick was in there.
  3. Find the real domain. First slash, then read backwards to the last dot before it. That is the owner.
  4. Reach support your own way instead. Type the brand's domain yourself, or open the app you already have installed, or use the number printed on the back of your card or on your invoice.
  5. Check the domain if you want a second opinion. Paste it into IP Tracker and see what comes back before you type anything into the page.

Of course, step four is the one that actually saves you, and it costs about twenty seconds. The check is for when you want to know what you were nearly caught by.

What does IP Tracker show you here?

IP Tracker is my free Chrome extension. You paste a domain, a link or a full email address, and it checks that value: 50 checks a day, no account, no tracking.

For a page like this, it gives you a handful of separate signals rather than a verdict. Whether the domain is a lookalike of one of about 125 widely impersonated brands, including banks, payment services, couriers, big tech, government sites, crypto and streaming. Whether Google Safe Browsing, Google's list of reported dangerous sites, has flagged it. How many security vendors flag it on VirusTotal. Community abuse reports on the address it resolves to. When the domain was registered, since a support desk for a twenty-year-old brand sitting on a domain created nine days ago is worth a raised eyebrow. And where it is hosted, which is how you notice a "global support centre" running on a free website builder.

What can't it do?

Unfortunately, quite a lot, and you should know the edges before you lean on it:

"Not flagged" is not the same as "safe". IP Tracker flags what it can see and shows you the evidence. It does not block anything, it cannot stop a call you decide to make, and a clean result is a missing signal, not a promise.

The pop-up era trained us to spot scams by how loud they were. That training has quietly expired. The new ones are calm, well-designed and reachable from a normal search, so the thing to check is no longer how the page feels, but who owns the address it lives at 🤓

To summarize:

Happy checking! 😎

Sources