Connect with us

Technology

Fake error popups are spreading malware fast

Published

on

Fake error popups are spreading malware fast

NEWYou can now listen to Fox News articles!

A dangerous cybercrime tool has surfaced in underground forums, making it far easier for attackers to spread malware. 

Instead of relying on hidden downloads, this tool pushes fake error messages that pressure you into fixing problems that never existed. Security researchers say this method is spreading quickly because it feels legitimate. The page looks broken. The warning feels urgent. The fix sounds simple. 

That combination is proving alarmingly effective for cybercriminals.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

How fake error malware attacks actually work

These attacks begin with a compromised website. When a visitor lands on the page, something looks wrong right away. Text appears broken. Fonts look scrambled. Visual elements seem corrupted. A pop-up then appears claiming the issue can be fixed with a browser update or a missing system font. A button offers to repair the problem instantly. 

Clicking that button copies a command to the clipboard and displays instructions to paste it into PowerShell or a system terminal. That single step launches the infection.

MALICIOUS CHROME EXTENSIONS CAUGHT STEALING SENSITIVE DATA

Fake error popups make a website look broken by scrambling text or fonts to create urgency and panic. (Jens Büttner/picture alliance via Getty Images)

Why this new tool changes the threat landscape

The tool behind these attacks is called ErrTraffic. It automates the entire process and removes the technical barriers that once limited cybercrime operations. For about $800, attackers get a full package with a control panel and scripted payload delivery. Analysts at the Hudson Rock Threat Intelligence Team identified the tool after tracking its promotion on Russian-language forums in early December 2025. 

Advertisement

ErrTraffic works through a simple JavaScript injection. A single line of code connects a hacked site to the attacker’s dashboard. From there, everything adapts automatically. The script detects the operating system and browser. It then displays a customized fake error message in the correct language. The attack works across Windows, Android, macOS and Linux.

MOST PARKED DOMAINS NOW PUSH SCAMS AND MALWARE

The popups often claim a browser update or missing system font is needed to fix the problem. (Daniel Acker/Bloomberg via Getty Images)

Why security software struggles to stop it

Traditional malware defenses look for suspicious downloads or unauthorized installations. ErrTraffic avoids both. Browsers see normal text copying. Security tools see a legitimate system utility being opened manually. Nothing appears out of place. That design allows the attack to slip through protections that would normally stop malware in its tracks.

The success rate is deeply concerning

Data pulled from active ErrTraffic campaigns shows conversion rates approaching 60%. That means more than half of the visitors who see the fake error message follow the instructions and install malware. Once active, the tool can deliver infostealers like Lumma or Vidar on Windows devices. Android targets often receive banking trojans instead. The control panel even includes geographic filtering, with built-in blocks for Russia and neighboring regions to avoid drawing attention from local authorities.

Advertisement

What happens after infection?

Once malware is installed, credentials and session data are stolen. Those compromised logins are then used to breach additional websites. Each newly hacked site becomes another delivery vehicle for the same attack. That cycle allows the campaign to grow without direct involvement from the original operator.

FAKE WINDOWS UPDATE PUSHES MALWARE IN NEW CLICKFIX ATTACK

Following the on-screen instructions can quietly trigger malware that steals passwords and personal data. (Kurt Knutsson)

Ways to stay safe from fake error malware

A few smart habits can significantly reduce risk when facing fake error pop-ups and browser-based traps.

1) Never run commands suggested by a website

Legitimate websites never ask you to copy and paste commands into PowerShell or a system terminal. Fake error malware relies on convincing messages that pressure you into doing exactly that. If a page instructs you to run code to fix a problem, close it immediately.

Advertisement

2) Close pages that claim your system is corrupted

Fake error campaigns often use broken text, scrambled fonts or warnings about missing files to grab attention. As a result, these visuals create urgency and trigger fear. In reality, a real system problem never announces itself through a random website, so close the page right away.

3) Install updates only through official system settings

Real browser and operating system updates come from built-in update tools, not pop-ups on websites. If an update is needed, your device will notify you directly through system settings or trusted app stores.

4) Install strong antivirus software on every device

Strong antivirus software can help block malicious scripts, detect infostealers and stop suspicious behavior before damage spreads. This is especially important since fake error malware targets Windows, Android, macOS and Linux systems.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

Advertisement

5) Use a data removal service to reduce exposure

Stolen credentials fuel the spread of fake error malware. Removing personal information from data broker sites can reduce the impact if login details are compromised and limit how far an attack can spread.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

6) Treat font and browser update pop-ups with suspicion

Claims about missing fonts or outdated browsers are a hallmark of these attacks. Modern systems manage fonts automatically, and browsers update themselves. A webpage has no reason to request manual fixes.

Advertisement

If a real update is needed, the operating system will request it directly. A random webpage never should.

Kurt’s key takeaways 

Fake error malware works because it plays on a very human reaction. When something on a screen suddenly looks broken, most people want to fix it fast and move on. That split-second decision is exactly what attackers are counting on. Tools like ErrTraffic show how polished these scams have become. The messages look professional. The instructions feel routine. Nothing about the moment screams danger. But behind the scenes, one click can quietly hand over passwords, banking access and personal data. The good news is that slowing down makes a real difference. Closing a suspicious page and trusting built-in system updates can stop these attacks cold. When it comes to pop-ups claiming your device is broken, walking away is often the smartest fix.

Have you ever seen a pop-up or error message that made you stop and wonder if it was real? Tell us what it looked like and how you handled it by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter. 

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Google pulls AI overviews for some medical searches

Published

on

Google pulls AI overviews for some medical searches

In one case that experts described as “really dangerous”, Google wrongly advised people with pancreatic cancer to avoid high-fat foods. Experts said this was the exact opposite of what should be recommended, and may increase the risk of patients dying from the disease.

In another “alarming” example, the company provided bogus information about crucial liver function tests, which could leave people with serious liver disease wrongly thinking they are healthy.

Continue Reading

Technology

10 ways to protect seniors from email scams

Published

on

10 ways to protect seniors from email scams

NEWYou can now listen to Fox News articles!

Email scams have become one of the fastest ways scammers steal money from older adults. A single click can expose bank accounts, personal data and retirement savings built over a lifetime. That growing risk is what prompted Bob to write to us with a question many families are now facing:

Advertisement

“My friend’s father is 95 and absolutely lives through his phone/laptop. He refuses to give up either and often clicks on email links. A few years ago, he got caught up in a gift card scam that almost cost him his life savings. It’s not taking away the car keys anymore; it is taking away the email and access to online banking! What do you recommend that his daughter do to protect his online presence?”

Bob is right. For many seniors, email and online banking have replaced car keys as the most dangerous access point. The goal is not to take devices away. It is to quietly put guardrails in place so one bad click does not turn into a financial disaster.

Here is a practical plan families can actually use.

HACKERS ABUSE GOOGLE CLOUD TO SEND TRUSTED PHISHING EMAILS

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

 1) Separate money from daily email use

Start by limiting how much damage a single click can cause. If possible, remove online banking access from the devices used for email. When that is not realistic, open a second checking account with only everyday spending money and link it to a debit card for routine purchases.

Keep primary savings accounts offline or set to view-only access. If available, require in-branch or phone verification for transfers above a set amount. This way, even if credentials are compromised, the largest accounts remain protected. 

2) Lock down email to stop scams targeting seniors

Email is the number one entry point for scams targeting seniors. Strong filtering matters. Use an email provider with advanced spam protection, such as Gmail or Outlook.com. In the email settings:

  • Turn off automatic image loading
  • Disable link previews
  • Block or auto-quarantine attachments from unknown senders
  • Automatically move messages from unknown senders to a Review folder

If available, enable warnings for emails that use familiar display names but come from unfamiliar addresses. This helps stop impersonation scams that pretend to be family, banks or service providers. These steps slow scammers down and reduce impulse clicks before damage happens.

Email is dominant, but voicemail and callback scams are also growing fast among seniors, often as a follow-up to phishing emails. If possible, silence unknown callers and block voicemail-to-email transcription for unfamiliar numbers, since many scams now start with urgent callback messages rather than links.

Email scams often start with messages that look routine but hide urgent threats designed to trigger quick clicks. (Kurt “CyberGuy” Knutsson)

Advertisement

3) Add a trusted second set of eyes

Next, add safety nets that notify family members when something looks wrong. Enable banking alerts for large withdrawals, new payees, password changes, unusual logins and new device sign-ins. Add his daughter as a trusted contact wherever the bank allows it. If available, enable delays or approval requirements for first-time transfers to new payees. This creates a cooling period that can stop scam-driven transactions. For email accounts, set up a recovery contact so that his daughter is notified immediately if someone attempts to access or reset the account.

Enable two-factor authentication (2FA) on email and banking accounts, but pair it with device and transfer alerts, since many scams now succeed even when 2FA is enabled.

4) Harden devices so clicks do not equal catastrophe

Devices should be set up to fail safely. Keep operating systems and browsers updated. Make sure the laptop uses a standard user account instead of an administrator account. This prevents software from installing without approval. Install real-time protection that blocks scam sites before they load. Strong antivirus software helps block malicious links and fake login pages automatically.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

Advertisement

5) Use a password manager to block fake logins

Password reuse makes scams far more dangerous. Fake pop-ups and lookalike websites are designed to trick people into typing usernames and passwords by hand. A password manager removes that risk by storing credentials securely and autofilling them only on legitimate websites. If a page is fake or malicious, the password manager will not fill anything. That simple refusal often prevents account takeovers before they start. Password managers also reduce frustration by eliminating the need to remember or reuse passwords across email, banking and shopping accounts. When set up correctly, this protection works quietly in the background on both phones and laptops.

Many phishing scams no longer rely on obvious fake emails. They rely on realistic login pages. Autofill protection is one of the most effective ways to stop these attacks without changing daily habits.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.

MALICIOUS CHROME EXTENSIONS CAUGHT STEALING SENSITIVE DATA

Advertisement

6) Freeze credit and monitor identity exposure

If scammers already have personal information, prevention alone is not enough. Freeze credit with Experian, TransUnion and Equifax to prevent new accounts from being opened. Also, place freezes with ChexSystems and the National Consumer Telecom and Utilities Exchange to stop criminals from opening bank accounts, phone lines, or utility services in his name.

If possible, request an IRS Identity Protection PIN to prevent tax-related identity theft.

Add ongoing identity monitoring so suspicious activity triggers alerts quickly. Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

7) Set clear rules around scams and payments

Technology helps, but expectations matter. Have one calm conversation and agree on simple rules:

Advertisement
  • No gift cards for urgent emails or texts
  • No sending money through unfamiliar apps or cryptocurrency
  • Always call a trusted family member before acting on urgency

Post these rules near the computer or phone. Visual reminders reduce panic decisions. Also, before setting rules, choose one primary trusted contact. Multiple helpers can slow response during urgent scams and create confusion when fast decisions matter. That person should be the default call for anything urgent involving money, account access, or unexpected requests.

Adult children increasingly step in to help parents spot red flags before a simple mistake turns into a financial loss. (Kurt “CyberGuy” Knutsson)

8) Reduce exposure with a data removal service

Scammers often find seniors by pulling personal details from public data broker websites. These sites publish phone numbers, addresses, relatives and age information that make targeting easier. A data removal service works behind the scenes to opt seniors out of these databases and reduce how much personal information is publicly available online. Fewer exposed details means fewer scam calls, fewer phishing emails and fewer impersonation attempts. This step does not stop every scam, but it significantly lowers how often seniors are targeted in the first place.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

9) Use senior-friendly monitoring tools the right way

Many tools designed for child safety also work well for seniors when used thoughtfully. When configured correctly, they add protection without interfering with daily routines.

Advertisement

Below are device-specific steps families can use today.

iPhone and iPad

Apple’s built-in Screen Time tools provide strong protection without installing extra apps.

What to set up:

  • Open Settings and tap Screen Time
  • Turn on Screen Time for the device
  • Tap Content & Privacy Restrictions and turn it on
  • Under App Store Purchases, set app installs to Don’t Allow
  • Tap Web Content and limit access to approved or safe websites
  • Set a Screen Time passcode known only to the caregiver

If the caregiver wants remote visibility or control, add the device to Family Sharing and manage Screen Time from the caregiver’s Apple ID.

BROWSER EXTENSION MALWARE INFECTED 8.8M USERS IN DARKSPECTRE ATTACK

Why this helps: It blocks many scam sites, prevents accidental app installs and stops fake update prompts from causing damage.

Advertisement

Android phones and tablets

Android offers built-in protections and optional supervised controls.

What to set up:

Settings may vary depending on your Android phone’s manufacturer

  • Open Settings and go to Digital Wellbeing & parental controls
  • Turn on parental controls for the device
  • Restrict app installs and require approval for new downloads
  • Enable Safe Browsing and website filtering
  • Turn on alerts for new app installs and account changes

For families who want shared oversight, Google Family Link can be used to supervise app installs and receive alerts, as long as both parties agree.

Why this helps: Many Android scams rely on fake app installs. These settings block that path.

Windows computers

Windows protection works best when user accounts are set correctly.

Advertisement

What to set up:

  • Create a standard user account for daily use
  • Keep the caregiver account as the only administrator
  • Turn on Microsoft Family Safety if available
  • Enable SmartScreen and browser phishing protection
  • Block software installs without administrator approval

Why this helps: Malware often installs silently on admin accounts. This setup prevents that.

Mac computers

macOS includes built-in controls similar to those on iPhone and iPad.

What to set up:

  • Create a standard user account for the senior
  • Limit administrator access to a trusted caregiver
  • Open System Settings and enable Screen Time
  • Restrict app installs and system changes
  • Keep built-in malware and phishing protections enabled

Simple digital guardrails can reduce risk while allowing seniors to keep their devices and independence. (Kurt “CyberGuy” Knutsson)

Why this helps: It prevents fake software updates and malicious downloads from installing.

10) Best practices for all devices

  • Use alert-only or limited-control settings whenever possible
  • Review settings together so expectations are clear
  • Avoid tools that feel invasive or confusing
  • Focus on blocking harm, not monitoring behavior

This is not about spying. It is about adding digital seatbelts while preserving independence. When used respectfully, these tools reduce risk without changing daily habits.

Pro Tip: Use a secure email service for added privacy

For families looking to go a step further, switching to a secure email service can significantly reduce scam exposure. Privacy-focused email providers are designed to limit tracking, block hidden tracking pixels, and reduce how much data advertisers or scammers can collect from inbox activity. Many secure email services also offer disposable or alias email addresses for one-time signups. If an alias starts receiving spam or scam messages, it can be disabled without affecting the main email account. This makes it easier to keep a primary email address private and limit long-term exposure. Secure email platforms typically include features like encrypted messages, no advertising and stronger privacy controls. While switching email providers is optional, it can be a useful upgrade for seniors who receive large volumes of spam or have been repeatedly targeted by scams.

Advertisement

Why it matters: Less tracking means fewer scam attempts. Aliases reduce how often personal email addresses are exposed, without changing daily habits.

For recommendations on private and secure email providers that offer alias addresses, visit Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Kurt’s key takeaways

Protecting seniors online is not about control. It is about prevention. Email scams are designed to exploit trust and urgency, especially in people who did not grow up with digital threats. Smart guardrails protect independence while preventing irreversible mistakes. If email and banking are today’s car keys, families need modern safety features to go with them.

If your parent clicked a scam email right now, would you know before the money was gone? Let us know by writing to us at Cyberguy.com.

Advertisement

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Continue Reading

Technology

Musk says he’s going to open-source the new X algorithm next week

Published

on

Musk says he’s going to open-source the new X algorithm next week

In 2023, what was then still called Twitter, open-sourced at least portions of the code that decided what it served up in your feed. But that GitHub repository is hopelessly out of date, with the vast majority of the files appearing to be from the initial upload three years ago. Elon Musk says that in seven days, he will open-source X’s new algorithm and finally give people a peek behind the curtain and possibly a technical explanation as to why your feed is 90 percent rage bait.

Elon has always made promises to open-source parts of X, and has followed through to at least some degree, including Grok-1 in 2024. But xAI is now on Grok-3, and the Grok GitHub repository hasn’t been updated in two years. The timing of the announcement open-sourcing the X algorithm is also likely to be met with some suspicion, as Musk is fending off criticism from across the globe and the political spectrum regarding Grok’s willingness to make deepfake nudes.

Musk says this release of the X algorithm will include “all code used to determine what organic and advertising posts are recommended to users.” He also says this will be just the first, with updates coming every four weeks, and that those will include developer notes highlighting any changes. Of course, considering how things played out in 2023, you’ll have to forgive us for taking that promise with a grain of salt.

Continue Reading

Trending