Threats · 118 days ago
CypherLoc is built to slip past the tools defenders trust most. It only fully decrypts when the right URL fragment is present and integrity checks pass, so scanners, sandboxes, and test runs can see a blank page while real victims get the scareware.
Barracuda says it has observed about 2.8 million CypherLoc attacks since the start of 2026. The campaign starts with phishing links or attachments and then locks the browser, shows fake support prompts, and pushes victims toward a phone scam; the detection problem is the conditional payload delivery, not the lure itself.
1 source covering this story
Researchers Warn CypherLoc Scareware Has Targeted Millions of Users
Barracuda reveals new CypherLoc scareware has featured in nearly three million attacks
Part of the PlainSec briefing for 2026-05-20