Fake Avast Website Steals Users’ Credit Card Information

A sophisticated phishing scam impersonating Avast antivirus software is targeting French-speaking users across Europe.

The fake website tricks victims into surrendering full credit card details card number, expiration date, and CVV code by fabricating a €499.99 unauthorized charge and promising a quick refund.

This operation blends realistic branding, dynamic JavaScript for urgency, and real-time live chat to harvest payment data at scale, turning a static page into an interactive trap.

The phishing site mimics Avast’s official portal flawlessly. It loads the genuine Avast logo from the company’s content delivery network, ensuring the orange-and-white shield appears authentic.

Navigation links like “Home,” “My Account,” and “Help” replicate the real interface. A prominent orange warning box creates false pressure: it claims cancellation requests must be filed within 72 hours, yet transactions over 48 hours cannot be reversed a contradiction designed to rush users.

At the center is a forged transaction record showing a -€499.99 debit dated “today.” JavaScript pulls the visitor’s local system date on page load, making the charge feel immediate and personal, whether it’s February or August.

Fake Avast site: Request for victim’s card information (Source: malwarebytes)
Fake Avast site: Request for victim’s card information (Source: malwarebytes)

The fixed €499.99 amount strikes a balance: large enough to alarm but plausible for a subscription renewal. No real Avast account or transaction exists; it’s pure social engineering to evoke panic.

Phishing Form Captures Data With Technical Precision

The scam’s form starts innocently, requesting refund reasons via a dropdown (“Avast refund,” “Fraudulent transaction,” etc.) and full personal details: name, email, phone, address, city, region, and postal code.

This is framed as identity verification for refund processing. Submission triggers a modal that requests credit card information to “credit back” the payment.

To boost credibility, the page runs the Luhn algorithm a standard check banks use to validate card numbers rejecting invalid entries before transmission.

Fake Avast site: Your application is being processed (Source: malwarebytes)
Fake Avast site: Your application is being processed (Source: malwarebytes)

On “Confirm,” the data is posted as JSON to a backend send.php script, capturing everything: personal info, card number, expiry, and CVV.

Victims then see a fake confirmation “Your application is being processed,” with a button that urges them to “Uninstall Avast” a final ploy to turn off protective software.

A standout feature is the bottom-right Tawk. to live chat widget (account ID: 689773de2f0f7c192611b3bf, widget code: 1j27pp82q).

This legitimate support tool lets operators engage visitors in real time, reassuring hesitant users and resolving doubts, such as the 72/48-hour mismatch. It elevates the site from passive phishing to dynamic fraud.

Spotting and Stopping Refund Scams Like This

These Avast clones highlight broader refund-phishing trends affecting brands worldwide.

Key red flags include “today’s” dynamic dates, tight deadlines, full card re-entry demands, skipped account checks, suspicious live chats, uninstall prompts, and lookalike domains. Legitimate firms verify via official logins and never request CVV for refunds.

If caught, act fast: contact your bank to cancel the card, dispute charges, change linked passwords, and scan devices. Proactive defenses include updating software, enabling web protection in tools like Malwarebytes, and submitting suspected files to services like Malwarebytes Scam Guard.

Users should always navigate directly to the official site (avast.com) and avoid unsolicited links.

Avast has warned about these scams via official channels; report incidents to them and to authorities such as France’s cybercrime unit.

This campaign underscores phishing’s evolution technical finesse meets psychological manipulation. Stay vigilant to avoid becoming the next statistic.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories