logo

Heavy Obfuscation Used By Fake Antivirus Websites

ID: 677f8c8a-bf26-58cd-8581-676935d08ef7

STIX ID: report--677f8c8a-bf26-58cd-8581-676935d08ef7

Feed Name: Zscaler Security Research Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a set of malicious fake‑antivirus web pages that use multi-layer, randomized JavaScript obfuscation to render frightening security warnings and coerce visitors into downloading fake AV installers that lead to further malware. The author decodes the layered scripts with Malzilla, documents the consistent obfuscation structure (only variable names randomized), and highlights that the heavy obfuscation reduces detection by antivirus solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.