Barracuda Research, the threat intelligence arm of Barracuda, has identified a web-based scareware kit designed to pressure victims into calling fraudulent technical support numbers through fake browser security alerts and aggressive user interface manipulation.
In a blog post, Barracuda Networks associate threat analyst Megharaj Balaraddi outlined how the attack framework, known as CypherLoc, represents an evolution in scareware tactics, shifting away from traditional malware downloads toward browser-based social engineering attacks that are more difficult for security tools to detect.
According to Balaraddi, around 2.8 million attacks featuring the CypherLoc kit have been observed since the start of 2026.
You might also be interested: Survey shows growing gap between privacy awareness and data control
How the attack unfolds
Balaraddi detailed how the attack typically begins with a phishing email containing a malicious link embedded either within the message body or an attachment. Victims who click the link are directed to a seemingly harmless webpage that gradually transitions into a full-screen scareware environment.
Once activated, the page displays alarming security warnings, locks the browser and urges users to immediately contact an unknowingly fraudulent support number. At the same time, if someone tries to inspect or examine the page while itโs running, the page deliberately causes the browser to become slow, glitchy or unstable.
โFor the victim, this reinforces the illusion of a serious system issue,โ Balaraddi said.
Stealth and evasion techniques
Balaraddi added the campaign uses several techniques to evade detection, including encrypted payloads, condition-based execution, and page replacement during runtime.
โCypherLoc shows how modern scareware is shifting away from obvious malware and toward browser-based, user-manipulation attacks that are difficult to detect and highly effective,โ he said.
According to Balaraddi, CypherLoc hides its malicious functionality inside an encrypted payload embedded directly within the webpage. The payload only decrypts if specific conditions are met, including the presence of a required URL fragment and passes a series of cryptographic integrity checks.
If the page is opened in a scanner, sandbox or testing environment, the malicious code refuses to run and instead redirects users to a blank screen, helping conceal the attack from automated security tools.
โCypherLoc relies on stealth and user concern, using the browser to pressure victims into scamming themselves,โ Balaraddi said.
โBy combining encryption, conditional execution, aggressive user interface abuse, and analysis disruption, it creates a convincing illusion of system compromise while keeping its technical footprint clean and maintaining a low network profile.โ
Also read: What is McAfee WebAdvisor? Should I uninstall it?