Hidden Browser Scareware Evades Scanners at Scale

CypherLoc is built to slip past the tools defenders trust most. It only fully decrypts when the right URL fragment is present and integrity checks pass, so scanners, sandboxes, and test runs can see a blank page while real victims get the scareware. Barracuda says it has observed about 2.8 million CypherLoc attacks since the start of 2026. The campaign starts with phishing links or attachments and then locks the browser, shows fake support prompts, and pushes victims toward a phone scam; the detection problem is the conditional payload delivery, not the lure itself.

Part of the PlainSec briefing for 2026-05-20

Sources