AI is making fake antivirus renewal pages harder to spot

Published

The page told a Belgian visitor that their Avast Premium Security subscription had just renewed for 129.99 euros, that it covered five devices, and that it would renew again in February. There was a green tick, a status badge reading Active, and a tidy summary table laying out the amount, the payment method and the dates. None of it was true: no subscription, no charge, no connection to Avast, whose branding was being used without permission.

What made this one worth writing up wasn't the lie. It was the polish, and two notes the builder left behind in the code.

Malwarebytes' threat intelligence team found the site during routine scam hunting and published its analysis on 16 September, describing a page noticeably better made than most of what it sees and carrying several signs it was produced with an AI assistant's help. The full write up is here.

The form is the lure, the call is the attack

These scams open with a message claiming your subscription has renewed automatically. Follow the instructions to cancel and you land on a page like this one. The cancellation form asked for a full name, an email address and a Belgian mobile number. That's all: no password field, no card details.

Malwarebytes suggests the restraint is deliberate. Three harmless looking details are far easier to hand over than a login page, and a working mobile number attached to a real name is exactly what the next stage needs: a call from someone posing as support staff, who'll try to talk the victim into installing remote access software.

Two notes meant for the boss, not the victim

The page carried two comments in its code that were never meant to be seen. Both were written in polite French and addressed to whoever had commissioned the work, explaining that the form didn't yet send anything anywhere and that a real submission process would need connecting later. Malwarebytes reads them as a contractor handing over an unfinished job rather than a scammer's note to self, and observes that a courteous second person summary of what still needs doing is very much how an AI assistant signs off.

Other details point the same way. Leftover styling sat in the code for a section that had been deleted, and the copy was grammatically clean but empty: four paragraphs on the subscription's benefits without naming one actual Avast feature. Real marketing copy names the product.

Malwarebytes is careful about how far this goes. Generated code carries no watermark, so AI involvement can't be proven from the files alone; the signs are consistent with it, no more. The page also looks abandoned before it ever worked. The form sent nothing anywhere, and two pieces of text would have shown up as visible gibberish had anyone opened it in a browser. Half built, Malwarebytes suggests, or a template waiting to be sold on.

The old advice has stopped working

For twenty years the guidance on spotting a fake was to look for the seams: bad grammar, the wrong currency, a stretched logo. That's now close to useless. An AI assistant produces fluent copy and a tidy layout on request, and the same builder can have a Dutch or German version, or one impersonating a different brand, in minutes. IntelFusions covered a related campaign in August, where fake Avast and CNN download pages handed attackers remote control of the PC.

So judge the situation rather than the page. If a message says a payment has been taken, check your bank statement directly; if the charge isn't there, there's nothing to cancel. Don't use the link you were sent, open the company's own app and sign in. And treat any cancellation flow whose main interest is your phone number as suspect, because a company you already pay knows how to reach you.

The page was aimed at Belgium, in French, with a Belgian number field, the kind of localisation that used to cost a scammer real effort and now costs a sentence of instruction. Our Belgium country profile tracks the wider threat picture there. The scam's shape hasn't changed at all. Only the finish has improved, which means the finish is no longer evidence of anything.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions