CyberGlossary

Malware

Scareware

Also known as: Fake-alert malware, Fear-based malware

Definition

Malicious software or web content that uses fake alarming messages to scare victims into installing junk software, paying for fake services, or calling fraudsters.

Scareware relies on social engineering rather than technical exploits: pop-ups, full-screen warnings, or fake antivirus scans claim the device is infected with dozens of threats and pressure the user to act immediately. Clicking through typically installs rogue security software, signs the victim up for a paid "licence," or routes them to a tech-support scam call centre that takes remote control of the device. Some variants drop real malware on top. Defences include ad and pop-up blockers, browser warning systems, application allow-listing, awareness training, and removing local administrator rights so a user cannot easily install rogue installers.

Examples

  • A browser pop-up claiming "Your PC is infected!" and pushing users to download a fake antivirus.
  • Full-screen lockers that mimic FBI warnings demanding a fine via prepaid cards.

Related terms