Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-impersonation-fraudvoice-social-engineeringphishing-campaign-intelligencecredential-access-method

Brand-impersonation scams using fake support channels to steal credentials and financial data

Updated 3mo agoFirst seen Feb 24, 20264 sources

Multiple brand-impersonation scams are targeting consumers by pushing them to interact with fake customer support and surrender sensitive data. One campaign uses a fraudulent site styled as Avast to convince French-speaking users they were charged €499.99 and must act quickly to “cancel” and receive a refund; the page dynamically inserts the current date via JavaScript, loads the Avast logo from Avast’s own CDN to appear legitimate, and then harvests full payment-card details (PAN, expiry, and CVV) via a cancellation/refund form.

Separate but related social-engineering activity targets Robinhood users with “security alert” SMS and email lures that direct victims to call scam call-center numbers, where operators attempt to extract login credentials, 2FA codes, and other personal/financial information; the email variant also commonly pushes victims toward installing remote-access tools such as AnyDesk or TeamViewer under the guise of support. In another consumer fraud pattern, scammers posing as a mobile carrier (e.g., Spectrum) call shortly after a phone delivery, claim the wrong device was shipped, and trick the recipient into mailing the phone to the attacker—enabling resale and potential identity-fraud follow-on if the device/line is activated under the victim’s details.

Share:
Brand-impersonation scams using fake support channels to steal credentials and financial data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 24, 20264mo ago

Phone return scam targets recent mobile phone buyers

A social-engineering scam targeted people who had just received new phones, with callers impersonating carriers and claiming the wrong device had been shipped so it needed to be returned. The fraud used urgency, knowledge of order details, and sometimes QR-code shipping workflows to facilitate theft of the device.

Robinhood scam texts push victims to fraudulent support lines

A related Robinhood scam campaign used SMS messages such as fake withdrawal-code alerts and phone-number-change notices to get recipients to call attacker-controlled support numbers. The call-center-style operation then socially engineered victims into disclosing account, personal, and financial information.

Avast-themed refund phishing campaign targets French-speaking users

A phishing campaign impersonating Avast used a fake €499.99 charge and refund/cancellation pretext to trick French-speaking users into submitting personal and payment card details. The scam site mimicked Avast branding, validated card numbers, and sent captured data to a backend endpoint while using live chat to pressure victims.

Feb 23, 20264mo ago

Robinhood phishing emails lure victims to fake support numbers

A scam campaign impersonating Robinhood sent fake security-alert emails claiming a login from a new device and urging recipients to call fraudulent customer-support numbers. The operators attempted to steal credentials, 2FA codes, wallet recovery phrases, or persuade victims to transfer funds and install remote-access tools.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
7 linked
AndroidTeamviewerAnydeskIphoneChatgptChatgptAndroid
Organizations
13 linked
MalwarebytesAvastTawk.toRobinhood Markets, Inc.FedexComcastCharter CommunicationsZimperiumZDNETAnyDesk Software GmbHTeamviewerGetty ImagesiStock
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Brand-impersonation scams using fake support channels to steal credentials and financial data | Mallory