Fake Avast Renewal Page Feeds a Support Scam

Help Net Security · Medium sophistication
Last updated September 17, 2026

Malwarebytes found a convincing fake “Avast Premium Security” renewal page targeting users in Belgium, claiming a €129.99 renewal and pushing visitors toward a cancellation flow. The real goal is to harvest a victim’s name, email, and mobile number so scammers can call next while posing as support and pressure the victim into installing remote access tools or “reversing” a payment that never happened.

Key findings

  • Researchers found a scam page impersonating Avast and targeting Belgium-based users with a fake renewal for €129.99 covering five devices.
  • The page uses a cancellation form to collect name, email, and Belgian mobile number, data that feels “harmless” to provide.
  • The collected phone number enables a follow-on support-style phone call aimed at getting the victim to install remote access software or assist with a fake refund/payment reversal.
  • Malwarebytes notes signs the page may have been built with AI (polished layout, AI-like “handover” comments in code), reducing the usefulness of old “look for sloppy errors” advice.
  • A professional-looking page is no longer a reliable indicator of legitimacy because scammers can use AI and copy real logos.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT helpdesk.
  • Affected industries: Consumers / general public, IT / cybersecurity software users.
  • Attack channels: website, vishing.
  • Impersonated: Avast (Avast Premium Security), Avast support staff.

Awareness takeaways

  • Treat unexpected ‘subscription renewed’ notices as suspicious, verify directly in the official vendor account or app, not via a cancellation link/form.
  • Don’t share your phone number (or other contact details) on cancellation/refund pages you reached via a link, scammers use it to trigger persuasive follow-up calls.
  • Be especially cautious if “support” asks you to install remote access tools or help ‘reverse’/refund a charge, stop and verify through a trusted channel.
  • Don’t rely on poor grammar or ugly design as the main warning sign, scam pages can look professional now.

Red flags to watch for

  • Unexpected renewal claim and urgency to “cancel” something you didn’t buy
  • Cancellation process asks for personal contact details instead of logging into your real account
  • Branding looks real, but the page is not connected to the vendor
  • Caller creates pressure around a charge that ‘already happened’
  • Request to install remote access software is disproportionate for a subscription question
  • You’re being asked to act on a payment that you cannot verify in your real account/bank
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You open a page that screams: "Your Avast Premium Security subscription has renewed for €129.99." Panic, right? This fake Avast page targets Belgium and pushes a "cancellation" form: name, email, Belgian mobile. It looks legit, but there is no subscription, no charge, and no link to Avast at all. The "aha" here: that harmless phone number is the whole scam. They use it to call you as fake Avast support, pressure you about this imaginary €129.99, and talk you into installing remote access tools or "reversing" a payment that never happened. If you see an unexpected antivirus renewal like this, do one thing: ignore the page, and check your real subscription or bank directly, never through the cancellation form or a follow-up call.

Categories

Similar attacks

Fake Avast Renewal Page Lures Victims Into Calls

Fake Avast Renewal Page Lures Victims Into Calls

Researchers found a realistic-looking fake Avast renewal page that claims a subscription renewed for €129.99 and pushes victims to “cancel” by entering their name, email, and mobile number. The charge is fake, and the real goal is to collect contact details so scammers can follow up with a phone…

September 16, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Vishing + Phishing Drive Major Data Theft Claims

Vishing + Phishing Drive Major Data Theft Claims

This weekly threat bulletin highlights multiple real-world incidents, including a healthcare data breach claim where attackers reportedly used phone-based social engineering (vishing) to compromise identity accounts and access cloud apps. It also describes a large-scale “debt relief” email phishing…

August 31, 2026