Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account Maintenance Update")

Malwarebytes Subscription Renewal Scam (TL-2026-0936), also tracked as Account Maintenance Update scam, is a medium-severity phishing campaign, first published 2026-06-24. It has no confirmed attribution, affects Malwarebytes Malwarebytes consumer subscriptions (impersonated brand), maps to 19 MITRE ATT&CK techniques (T1056, T1204, T1204.001), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-0936

Threat ID
TL-2026-0936
Also known as
Account Maintenance Update scam, Fake Malwarebytes renewal scam, Malwarebytes invoice refund-bait campaign
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-06-24
Last reviewed
2026-06-24
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, retail, financial, technology
Target regions
North America, United States
Detection rules
9
Indicators of compromise
25

An active brand-impersonation scam emails fraudulent Malwarebytes subscription-renewal invoices (subject "Account Maintenance Update", $276.50 for a fictitious "Ultimate Security Pack") that pressure recipients to call +1 (810) 210-5434 or click a dispute link. The callback funnels victims into a tech-support / refund-bait scam toward payment fraud, credential theft, and remote-access abuse; sibling variants impersonate PayPal, Amazon, and Geek Squad.

How Malwarebytes Subscription Renewal Scam works

Malwarebytes Labs documented an active subscription-renewal scam in which threat actors impersonate Malwarebytes to deliver fraudulent invoice emails. The lure email carries the subject line "Account Maintenance Update" and contains official-looking but entirely fabricated billing artifacts: invoice reference INV-ZIDNQCWSMO, activation code 8fd14ea8-4014-4430-ba19-313554098112, a charge of $276.50 USD, and a made-up product "Ultimate Security Pack" with a "3 Years, 3 Devices" license term. The charge is deliberately large enough to provoke alarm, and the message ends with a callback number (+1 (810) 210-5434) or a "dispute the charge" link, steering the recipient away from legitimate billing channels.

The campaign is a classic callback-phishing / TOAD (telephone-oriented attack delivery) operation. Because the email frequently carries no malicious attachment or link, it evades content-scanning controls and relies entirely on social engineering. Senders use compromised mailboxes or lookalike domains so the sender address does not belong to the company being impersonated. Once a victim calls, the actor escalates through a standard tech-support-scam playbook: requesting remote-access software to the victim's machine, directing the victim to log into online banking, processing a fake refund through a spoofed website that harvests card/banking credentials, then claiming an "over-refund" was issued and demanding repayment via gift cards, cryptocurrency, wire transfer, or payment apps. Some variants pivot the impersonated brand to PayPal or other payment providers and direct victims to phishing sites that steal banking credentials.

This activity sits inside a broader refund-bait ecosystem reported by Malwarebytes in 2026. A March 2026 variant abused Google/Outlook calendar invites to plant fake Malwarebytes renewal notices, using callback numbers in the 810 (Michigan) and 865 (Tennessee) area codes — the same 810 prefix as this campaign's +1 (810) 210-5434, indicating a shared or co-located scam-call infrastructure cluster. A June 2026 Malwarebytes investigation caught a fake-invoice kit mid-construction (templates still contained unfilled placeholders #TFN#, #PRICE#, #DATE#, #EMAIL#) impersonating PayPal, Amazon, and Geek Squad, staged on a family of throwaway .xyz "invoice" domains (invoicepdfin.xyz, invoicepdfus.xyz, invoicepdfusa.xyz, invoicerep.xyz, invoicestatement.xyz, invoicestm.xyz) with callback numbers 804-392-2793 and 801-640-8589 and charge amounts such as $349, $499, and $598.96. This is not a software vulnerability and carries no CVE; it is an active, financially motivated social-engineering campaign with extractable indicators that warrant defender awareness, user-reporting workflows, and SOC blocklisting of the callback numbers and staging domains.

MITRE ATT&CK techniques used in TL-2026-0936

Collection

T1056 Input Capture

Execution

T1204 User Execution; T1204.001 Malicious Link

Command and Control

T1219 Remote Access Tools

Initial Access

T1566 Phishing; T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice

Resource Development

T1583 Acquire Infrastructure; T1583.001 Domains; T1583.004 Server; T1586.002 Email Accounts; T1608.001 Upload Malware

Reconnaissance

T1589 Gather Victim Identity Information; T1589.002 Email Addresses; T1598 Phishing for Information; T1598.003 Spearphishing Link; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Malwarebytes Subscription Renewal Scam

  • Malwarebytes — Malwarebytes consumer subscriptions (impersonated brand)
    Vulnerable versions: N/A — brand impersonation, not a product flaw
  • PayPal / Amazon / Geek Squad — Payment & retail brands impersonated by sibling variants
    Vulnerable versions: N/A — brand impersonation

Remediation for Malwarebytes Subscription Renewal Scam

Immediate actions

  • Do not call phone numbers or click links contained in unsolicited renewal/invoice emails; verify any charge by logging into the vendor's official site directly.
  • Block the callback numbers (+1 810-210-5434 and the related 810/865/804/801 cluster) at the telephony/PBX and SOAR-enrichment layer.
  • Block and sinkhole the invoice-themed .xyz staging domains at the secure web gateway / DNS resolver.
  • Report received samples to the impersonated vendor's abuse channel and to IC3 (https://ic3.gov) / FTC (https://ReportFraud.ftc.gov).

Workarounds

  • Configure mail flow rules to quarantine or banner external mail spoofing the brand display name without aligned authentication.
  • Turn off automatic calendar event addition in Google Workspace / Microsoft 365.

Longer-term hardening

  • Deploy email authentication enforcement (SPF/DKIM/DMARC reject) and lookalike-domain monitoring for brand abuse.
  • Run security-awareness training specifically covering callback-phishing / refund-bait and 'over-refund' gift-card lures.
  • Restrict installation of remote-access software (AnyDesk/TeamViewer/UltraViewer/ScreenConnect) via application allowlisting.
  • Disable auto-add of calendar invites and restrict calendar sharing permissions to blunt the calendar-delivery variant.

Timeline of Malwarebytes Subscription Renewal Scam

  • The FTC publishes a consumer alert on fake Geek Squad renewal scams, documenting the antivirus/subscription refund-bait callback pattern (fake renewal invoice → call-this-number → over-refund repayment) that this 2026 Malwarebytes campaign directly continues.
  • KnowBe4 syndicates the calendar-invite variant ('Scammers Abuse Calendar Invites to Plant Phony Subscription Notices'), broadening awareness of the auto-added-invite delivery vector among security-awareness teams.
  • Malwarebytes Labs reports a sibling variant abusing Google/Outlook calendar invites to plant fake Malwarebytes renewal notices, using callback numbers in the 810 (Michigan) and 865 (Tennessee) area codes.
  • Malwarebytes catches a fake-invoice kit mid-construction — recovered templates still contain unfilled placeholders (#TFN#, #PRICE#, #DATE#, #EMAIL#) — impersonating PayPal, Amazon, and Geek Squad on a family of .xyz 'invoice' staging domains.
  • TL-Intel documents IOCs (callback numbers, invoice/activation references, staging domains) and TTPs for SOC blocklisting and user-reporting workflows.
  • Reporting syndicated to Security Boulevard, broadening defender awareness of the brand-impersonation refund-bait pattern.
  • Campaign confirmed active and ongoing; charges of several hundred dollars and pressure-to-call/dispute-link lures observed in the wild.
  • Malwarebytes Labs publishes 'Watch out for renewal scams pretending to be Malwarebytes', documenting the 'Account Maintenance Update' fake-invoice email (INV-ZIDNQCWSMO, $276.50, callback +1 810-210-5434).

Sources cited for Malwarebytes Subscription Renewal Scam

Threats related to Malwarebytes Subscription Renewal Scam

Detection coverage for TL-2026-0936

As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0936 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats