CyberGlossary

Malware

Rogue Security Software

Also known as: Fake antivirus, Rogueware

Definition

Fake antivirus or system-cleaning software that pretends to find threats and demands payment to fix them, while often installing real malware itself.

Rogue security software masquerades as a legitimate antivirus, anti-spyware, or PC cleaner product. After installation it runs a fake scan that always reports many "infections" and prompts the user to buy a paid license to remove them. The application typically does nothing useful, may degrade system performance, and frequently bundles real malware such as info stealers, adware, or backdoors. Distribution channels include scareware pop-ups, malvertising, software cracks, and bundled installers. Defences include using only reputable security products, blocking known rogue domains, enforcing application allow-listing, removing local admin rights, and educating users to ignore unsolicited "infection" warnings from web pages.

Examples

  • "SystemDoctor" and "WinFixer" families demanding payment to remove fictitious infections.
  • MacSweeper and MacKeeper-style products historically using aggressive scareware advertising.

Related terms